Lucene search

K
ibmIBMF2B7B33735F7B706B087CB888B9690EE4D2D390E6A699CFA4EF68615E7EDAE8B
HistoryApr 03, 2023 - 8:05 p.m.

Security Bulletin: IBM Aspera Faspex 5.0.5 has addressed CVE-2022-4304

2023-04-0320:05:38
www.ibm.com
20
ibm
aspera faspex
5.0.5
patches
openssl
cve-2022-4304
sensitve information
timing-based side channel
rsa decryption
vulnerability
fix
linux

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.4%

Summary

This Security Bulletin addresses OpenSSL CVE-2022-4304 where an attacker could obtain sensitve nformation, caused by a timing-based side channel in the RSA Decryption implementation.

Vulnerability Details

CVEID:CVE-2022-4304
**DESCRIPTION:**OpenSSL could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/246612 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product Version(s)
Aspera Faspex 5 5.0.4 and prior

Remediation/Fixes

It is recommended to apply the fix as soon as possible, see link below.

Product Fixing VRM Platform Link to Fix
IBM Aspera Faspex

5.0.5

| Linux| click here

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmaspera_streamingMatch1.0
OR
ibmaspera_faspexMatch5.0.4
OR
ibmaspera_faspex_on_demandMatch1.1
OR
ibmaspera_faspex_on_demandMatch3.7
OR
ibmaspera_faspexMatch1.0
OR
ibmaspera_faspexMatch1.1
OR
ibmaspera_faspex_on_demandMatch1.0

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.4%