Vulnerabilities > CVE-2024-6916 - Insecure Storage of Sensitive Information vulnerability in Zowe CLI

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
zowe
CWE-922

Summary

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

Vulnerable Configurations

Part Description Count
Application
Zowe
1

Common Weakness Enumeration (CWE)