IBM-XFORCE-255828: High severity ibm global security kit vulnerability
IBM GSKit information disclosure
Other sources
IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 255828.
Affected Software
Event History
Frequently Asked Questions
What is the severity of IBM-XFORCE-255828?
The severity of IBM-XFORCE-255828 is considered medium due to the potential for sensitive information disclosure.
How do I fix IBM-XFORCE-255828?
To fix IBM-XFORCE-255828, updating to the latest version of affected IBM HTTP Server and IBM GSKit is recommended.
What versions are affected by IBM-XFORCE-255828?
IBM-XFORCE-255828 affects IBM HTTP Server versions up to 8.5 and 9.0, as well as IBM GSKit.
What type of vulnerability is IBM-XFORCE-255828?
IBM-XFORCE-255828 is an information disclosure vulnerability caused by a timing-based side channel in RSA decryption.
Can IBM-XFORCE-255828 be exploited remotely?
Yes, IBM-XFORCE-255828 can be exploited remotely by sending numerous trial messages for decryption.