Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-43866
HistoryJun 01, 2023 - 12:00 a.m.

IBM Global Security Kit Encryption Issues Vulnerability

2023-06-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
22
ibm global security kit
encryption
vulnerability
ssl
tls
cryptographic issue
time-based
side-channel
rsa decryption
exploitation
sensitive information
trial messages
cnvd

EPSS

0.001

Percentile

41.3%

IBM Global Security Kit is a library and utility program for SSL or TLS communications from International Business Machines (IBM). The IBM Global Security Kit suffers from a cryptographic issue vulnerability that stems from a time-based side-channel in the RSA decryption implementation, which could be exploited by an attacker to decrypt and then obtain sensitive information by sending too many trial messages.

EPSS

0.001

Percentile

41.3%

Related for CNVD-2023-43866