CVE-2021-4314 - CVE House
Back to Database
Status published Unknown CVE-2021-4314

It is possible to manipulate the JWT token without the...

Vulnerability Description

It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What happens is that the services using the ZAAS client or the API ML API to query will be deceived into believing the information in the JWT token is valid when it isn’t. It’s possible to use this to persuade the southbound service that different user is authenticated.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-4314

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Open Mainframe Project

View all reports →

Affected Software

Zowe
Vulnerable Versions:
1.16.0

Timeline

Official Publish: January 18th, 2023
Last Modified: April 3rd, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)