{"id":"CVE-2024-9798","summary":"Health endpoint offers list of onboarded services to unauthenticated users","details":"The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.","modified":"2026-08-12T03:51:19.190730871Z","published":"2024-10-10T07:29:10.066Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9798.json","cna_assigner":"Zowe"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9798.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9798"},{"type":"PACKAGE","url":"https://github.com/zowe/api-layer"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zowe/api-layer","events":[{"introduced":"0d0685cd078acdc7204b1900654a7a78d5791c62"},{"fixed":"00655a6bfe28b56497dc659f8851b268b223a465"},{"introduced":"e9450a009fe42265526cd617cf993ead73fd028e"},{"fixed":"dae609200230d8fcd6b227a722a08c7edd47b582"}],"database_specific":{"cpe":"cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.28.8"},{"introduced":"2.0.0"},{"fixed":"2.18.0"}],"source":"CPE_RANGE"}}],"versions":["v2.17.4","v2.17.3","v2.17.2","Zowe_2.17.0","v2.17.1","v2.17.0","v2.16.3","v2.16.2","Zowe_2.16.0","v2.16.1","v2.16.0","v2.15.1","v2.15.0","Zowe_2.15.0","v2.14.8","v2.14.7","v2.14.6","v2.14.5","v2.14.4","Zowe_2.14.0","v2.14.3","v2.14.2","v2.14.1","v2.14.0","v2.13.7","v2.13.6","v2.13.5","v2.13.4","v2.13.3","v2.13.2","Zowe_2.13.0","v2.13.1","v2.13.0","v2.12.9","v2.12.8","v2.12.7","v2.12.6","v2.12.5","v2.12.4","v2.12.3","v2.12.2","Zowe_2.12.0","v2.12.1","v2.12.0","v2.11.5","v2.11.4","v2.11.3","v2.11.2","v2.11.1","v2.11.0","v2.10.15","v2.10.14","v2.10.13","v2.10.12","v2.10.11","v2.10.10","v2.10.9","v2.10.8","v2.10.7","v2.10.6","Zowe_2.10.0","v2.10.5","v2.10.4","v2.10.3","v2.10.2","v2.10.1","v2.10.0","v2.9.1","Zowe_2.9.0","v2.8.16","v2.8.15","v2.8.14","v2.8.13","v2.8.9","v2.8.8","v2.8.5","v2.8.4","v2.8.3","v2.8.2","v2.8.1","v2.8.0","v2.7.3","v2.7.2","v2.7.1","v2.7.0","Zowe_2.7.0","v2.6.5","v2.6.4","v2.6.3","v2.6.2","v2.6.1","v2.6.0","Zowe_2.6.0","v2.5.5","v2.5.4","v2.5.3","v2.5.2","v2.5.1","v2.5.0","Zowe_2.5.0","v2.4.19","v2.4.18","v2.4.17","v2.4.16","v2.4.15","v2.4.14","v2.4.13","v2.4.12","v2.4.11","v2.4.10","Zowe_2.4.0","v2.4.9","v2.4.8","v2.4.7","v2.4.6","v2.4.5","v2.4.4","Zowe_2.3.1","Zowe_2.3.0","v2.4.3","v2.4.2","v2.4.1","v2.4.0","v2.3.7","v2.3.6","v2.3.5","v2.3.4","v2.3.3","v2.3.2","v2.3.1","v2.3.0","v2.2.4","Zowe_2.2.0","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.1.3","v2.1.2","v2.1.1","v2.1.0","Zowe_2.1.0","v1.28.7","v1.28.6","v1.28.5","v1.28.4","v1.28.3","v1.28.2","v1.28.1","Zowe_1.28.0","v1.28.0","v1.27.26","v1.27.25","v1.27.24","v2.0.9","Zowe_2.0.0","v1.27.23","v1.27.22","v1.27.21","v1.27.20","v1.27.19","v1.27.18","v1.27.17","v1.27.16","v1.27.15","v1.27.13","v1.27.11","v1.27.5","v1.27.4","Zowe_1.27.0","v1.27.3","v1.27.2","v1.26.20","v1.26.19","v1.26.18","v1.26.17","v1.26.16","Zowe_1.26.0","v1.26.15","v1.26.13","v1.26.9","v1.26.8","v1.26.7","v1.26.6","v1.26.5","v1.26.4","v1.26.3","v1.26.2","v1.26.1","v1.26.0","v1.25.7","v1.25.6","v1.25.5","v1.25.4","Zowe_1.25.0","v1.25.3","v1.25.2","v1.25.1","v1.25.0","v1.24.7","v1.24.6","v1.24.5","v1.24.4","Zowe_1.24.0","v1.24.3","v1.24.2","v1.24.0","v1.23.8","v1.23.7","v1.23.6","v1.23.5","Zowe_1.23.0","v1.23.4","v1.23.3","v1.23.2","v1.23.1","v1.23.0","v1.22.4","Zowe_1.22.0","v1.22.3","v1.22.2","v1.22.1","v1.22.0","v1.21.13","v1.21.12","v1.21.11","Zowe_1.21.1","v1.21.10","v1.21.9","v1.21.8","v1.21.6","v1.21.5","v1.21.4","v1.21.3","v1.21.2","v1.20.19","v0.0.25","v1.20.18","v1.20.16","Zowe_1.20.0","v1.20.15","v1.20.14","v1.20.10","v1.20.1","v1.19.2","Zowe_1.19.0","v1.19.1","v1.20.0","v1.19.0","v1.18.1","Zowe_1.18.0","v1.18.0","v1.17.1","Zowe_1.17.0","v1.17.0","v1.16.0","Zowe_1.16.0","v1.15.0","Zowe_1.15.0","v1.14.0","Zowe_1.14.0","v1.13.0","Zowe_1.13.0","v1.12.2","Zowe_1.12.0","v1.12.1","v1.12.0","v11","v1.11.0","Zowe_1.11.0","v1.7.0","v1.6.0","v1.4.2","v1.4.1","v1.4.0","v1.3.4","v1.3.3","v1.3.2","v1.3.1","v1.2.2","v1.2.1","v1.2.0","v1.1.12","v1.1.11","v1.1.10","v1.1.9","v1.1.8","v1.1.7","v1.1.6","v1.1.5","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9798.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:F/RL:T/RC:C/CR:H/IR:H/AR:M/MAV:N/MAC:L/MPR:N/MUI:N/MS:C/MC:H/MI:H/MA:H"}]}