The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zowe_api_mediation_layer | Linuxfoundation | 1.0.0 (including) | 1.28.8 (excluding) |
Zowe_api_mediation_layer | Linuxfoundation | 2.0.0 (including) | 2.18.0 (excluding) |