CVE-2023-32342: IBM GSKit information disclosure
IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 255828.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32342?
CVE-2023-32342 is a vulnerability in IBM GSKit that allows a remote attacker to obtain sensitive information.
What is the severity of CVE-2023-32342?
The severity of CVE-2023-32342 is high, with a severity value of 7.
How does CVE-2023-32342 work?
CVE-2023-32342 is caused by a timing-based side channel in the RSA Decryption implementation of IBM GSKit, where an attacker can obtain sensitive information by sending an overly large number of trial messages for decryption.
What software is affected by CVE-2023-32342?
IBM HTTP Server versions 8.5 and 9.0 are affected by CVE-2023-32342.
How can I find more information about CVE-2023-32342?
You can find more information about CVE-2023-32342 on the IBM X-Force Exchange website and the MITRE CVE website.