First published: Wed May 24 2023(Updated: )
IBM GSKit information disclosure
Affected Software | Affected Version | How to fix |
---|---|---|
IBM HTTP Server | <=8.5 | |
IBM HTTP Server | <=9.0 | |
IBM Global Security Kit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of IBM-XFORCE-255828 is considered medium due to the potential for sensitive information disclosure.
To fix IBM-XFORCE-255828, updating to the latest version of affected IBM HTTP Server and IBM GSKit is recommended.
IBM-XFORCE-255828 affects IBM HTTP Server versions up to 8.5 and 9.0, as well as IBM GSKit.
IBM-XFORCE-255828 is an information disclosure vulnerability caused by a timing-based side channel in RSA decryption.
Yes, IBM-XFORCE-255828 can be exploited remotely by sending numerous trial messages for decryption.