The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Zowe_api_mediation_layer | Linuxfoundation | 1.0.0 (including) | 1.28.8 (excluding) | 
| Zowe_api_mediation_layer | Linuxfoundation | 2.0.0 (including) | 2.18.0 (excluding) |