CVE-2023-33850
IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://exchange.xforce.ibmcloud.com/vulnerabilities/257132, https://www.ibm.com/support/pages/node/7010369, https://www.ibm.com/support/pages/node/7022413, https://www.ibm.com/support/pages/node/7022414, https://security.netapp.com/advisory/ntap-20241108-0002/
