IBM GSKit-Crypto information disclosure
CVE-2023-33850
7.5HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 22 August 2023
What is CVE-2023-33850?
A vulnerability exists in IBM GSKit-Crypto due to a timing-based side channel in its RSA decryption implementation. An attacker could exploit this flaw by sending numerous trial messages, allowing for the potential extraction of sensitive information. This exploit highlights the importance of secure coding practices and the need for robust cryptographic implementations to prevent such information leakage.
Affected Version(s)
CICS TX Advanced 10.1, 11.1
CICS TX Standard 11.1
TXSeries for Multiplatforms 8.1, 8.2, 9.1