CVE-2023-33850

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:txseries_for_multiplatform:8.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:txseries_for_multiplatform:9.1:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:ibm:txseries_for_multiplatform:8.2:*:*:*:*:*:*:*
OR cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:standard:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:a:ibm:cics_tx:10.1:*:*:*:advanced:*:*:*
cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:advanced:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

27 Sep 2024, 14:15

Type Values Removed Values Added
Summary IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132. IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
References
  • {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/257132', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/257132', 'tags': ['VDB Entry', 'Vendor Advisory'], 'refsource': 'MISC'}

19 Sep 2024, 16:15

Type Values Removed Values Added
Summary IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132. IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132.

28 Aug 2023, 19:51

Type Values Removed Values Added
CWE CWE-203
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Ibm cics Tx
Ibm txseries For Multiplatform
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Hp hp-ux
Ibm aix
Hp
Ibm
CPE cpe:2.3:a:ibm:cics_tx:10.1:*:*:*:advanced:*:*:*
cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:advanced:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:txseries_for_multiplatform:8.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:txseries_for_multiplatform:8.1:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:txseries_for_multiplatform:9.1:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
References (MISC) https://www.ibm.com/support/pages/node/7010369 - (MISC) https://www.ibm.com/support/pages/node/7010369 - Vendor Advisory
References (MISC) https://www.ibm.com/support/pages/node/7022413 - (MISC) https://www.ibm.com/support/pages/node/7022413 - Vendor Advisory
References (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/257132 - (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/257132 - VDB Entry, Vendor Advisory
References (MISC) https://www.ibm.com/support/pages/node/7022414 - (MISC) https://www.ibm.com/support/pages/node/7022414 - Vendor Advisory

22 Aug 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-22 21:15

Updated : 2024-09-27 14:15


NVD link : CVE-2023-33850

Mitre link : CVE-2023-33850


JSON object : View

Products Affected

hp

  • hp-ux

ibm

  • txseries_for_multiplatform
  • cics_tx
  • aix

linux

  • linux_kernel

microsoft

  • windows
CWE
CWE-203

Observable Discrepancy