Zowe is an open-source framework providing command-line and API interfaces for mainframe systems, with its exposure concentrated in the Zowe CLI product around sensitive-information storage weaknesses. The vendor's vulnerability footprint reflects typical configuration and credential-handling concerns that arise in tools bridging modern development workflows to legacy enterprise platforms; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zowe over time
Of all the CVEs published by Zowe as a CNA, 14.3% affect products that Zowe develops as a vendor.
Of all the CVEs published that affect products developed by Zowe, 100.0% are self-published by Zowe as a CNA.
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6916MEDIUM A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag. | Jul 19, 2024 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zowe.
Media articles that mention a CVE ID that affects a product developed by Zowe — matched by CVE ID, not by vendor name.