Open Mainframe Project
CVE Severity Distribution (All Time)
Timeline Overview
Recent CVEs
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific info…
The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-in…
A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. Thi…
A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-ini…
A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update co…
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happ…