Weaker than expected cryptographic algorithms in Semeru Runtime versions 8.0.302.0 - 17.0.9.0
CVE-2024-22361

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
10 February 2024

What is CVE-2024-22361?

IBM Semeru Runtime versions ranging from 8.0.302.0 to 8.0.392.0, 11.0.12.0 to 11.0.21.0, 17.0.1.0 to 17.0.9.0, and 21.0.1.0 exhibit vulnerabilities due to usage of cryptographic algorithms that are weaker than expected. This vulnerability potentially enables attackers to decrypt sensitive information, posing serious security risks. The issue has been documented under IBM X-Force ID 281222, emphasizing the need for immediate attention and remediation measures to protect confidential data.

Affected Version(s)

Semeru Runtime 8.0.302.0 <= 8.0.392.0

Semeru Runtime 11.0.12.0 <= 11.0.21.0

Semeru Runtime 17.0.1.0 <= 17.0.9.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.