Zowe

First CVE: Jan 18, 2023Active for: 4 years
7
CVEs Published
More CVEs Published than 20% of tracked CNAs
3.5
Avg CVEs / Year
More Avg CVEs / Year than 25% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 18% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Zowe as a CNA, 14.3% affect products that Zowe develops as a vendor.

14.3%
85.7%
Self-reported: 1Third-party: 6

Of all the CVEs published that affect products developed by Zowe, 100.0% are self-published by Zowe as a CNA.

100.0%
Self-published: 1Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Zowe over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2023
3 years ago
Most Recent CVE
Oct 10, 2024
652 days ago

Top CVEs

All CVEs published by Zowe as a CNA, regardless of affected vendor or product.

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to th
Jul 17, 20249.025NONO
A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed e
Mar 1, 20237.824NONO
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation whe
Jan 18, 20235.319NONO
The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
Oct 10, 20245.318NONO
A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.
Jul 19, 20245.518NONO
A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.
Jul 17, 20245.918NONO
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, incl
Oct 10, 20245.317NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA7 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local3 (42.9%)
Network4 (57.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required1 (14.3%)
Privileges Required
Low3 (42.9%)
High0 (0.0%)
None4 (57.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Zowe as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Zowe as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs