CVE-2023-33850: IBM GSKit-Crypto information disclosure
IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-33850?
CVE-2023-33850 is a vulnerability in IBM GSKit-Crypto that allows a remote attacker to obtain sensitive information through a timing-based side channel in the RSA Decryption implementation.
How does CVE-2023-33850 work?
CVE-2023-33850 works by sending an overly large number of trial messages for decryption, which can be exploited by an attacker to obtain sensitive information.
What is the severity of CVE-2023-33850?
CVE-2023-33850 has a severity rating of 7.5 (high).
Which software products are affected by CVE-2023-33850?
IBM TXSeries for Multiplatforms versions 8.1, 8.2, and 9.1 are affected by CVE-2023-33850.
How can I fix CVE-2023-33850?
To fix CVE-2023-33850, apply the appropriate patch provided by IBM for your version of IBM TXSeries for Multiplatforms.