CVE-2023-33850
Summary
| CVE | CVE-2023-33850 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-22 21:15:00 UTC |
| Updated | 2023-08-28 19:51:00 UTC |
| Description | IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Bulletin: "Timing Oracle in RSA Decryption" issue may affect GSKit shipped with IBM CICS TX Advanced |
MISC |
www.ibm.com |
|
| Security Bulletin: Timing Oracle in RSA Decryption vulnerability might affect GSKit supplied with IBM TXSeries for Multiplatforms. |
MISC |
www.ibm.com |
|
| Security Bulletin: "Timing Oracle in RSA Decryption " issue may affect GSKit shipped with IBM CICS TX Standard |
MISC |
www.ibm.com |
|
| IBM X-Force Exchange |
MISC |
exchange.xforce.ibmcloud.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 20372 IBM DB2 information disclosure Vulnerability (7047481)
- 330167 IBM AIX Java Multiple Vulnerabilities (java_feb2024_advisory)
- 379387 IBM Java Software Development Kit (SDK) Security Vulnerability (7116432)
- 379431 IBM WebSphere Application ServerJava SDK Vulnerability (7058356)
- 755832 SUSE Enterprise Linux Security Update for java-1_8_0-ibm (SUSE-SU-2024:0605-1)
- 755835 SUSE Enterprise Linux Security Update for java-1_8_0-ibm (SUSE-SU-2024:0619-1)