CVE-2024-41760: IBM Common Cryptographic Architecture information disclosure
IBM CCA could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations.
Other sources
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51
could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41760?
CVE-2024-41760 is considered a high severity vulnerability due to the potential for sensitive information leakage through a timing attack.
How do I fix CVE-2024-41760?
To mitigate CVE-2024-41760, upgrade IBM Common Cryptographic Architecture to version 7.5.52 or later.
What products are affected by CVE-2024-41760?
CVE-2024-41760 affects IBM Common Cryptographic Architecture versions 7.0.0 through 7.5.51, as well as related toolkit products.
What types of attacks does CVE-2024-41760 enable?
CVE-2024-41760 allows attackers to exploit a timing attack to reveal sensitive information during RSA operations.
Is there a workaround for CVE-2024-41760?
While upgrading is the recommended solution, specific mitigations for timing attacks may include changing how RSA operations are implemented.