Executive Summary

Informations
Name CVE-2024-6834 First vendor Publication 2024-07-17
Vendor Cve Last vendor Modification 2024-08-01

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints requiring an internal client certificate without any credentials. It could lead to managing components in there and allow an attacker to handle the whole communication including user credentials.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6834

Sources (Detail)

https://github.com/zowe/api-layer
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
Date Informations
2024-08-01 21:27:34
  • Multiple Updates
2024-07-18 17:27:23
  • Multiple Updates
2024-07-17 21:27:24
  • First insertion