Vulnerability Details CVE-2023-33850
IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.0%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-33850
-
cpe:2.3:a:ibm:cics_tx:10.1
-
cpe:2.3:a:ibm:cics_tx:11.1
-
cpe:2.3:a:ibm:txseries_for_multiplatform:8.1
-
cpe:2.3:a:ibm:txseries_for_multiplatform:8.2
-
cpe:2.3:a:ibm:txseries_for_multiplatform:9.1
-
-
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-