Unrated severityNVD Advisory· Published Aug 22, 2023· Updated Nov 3, 2025
IBM GSKit-Crypto information disclosure
CVE-2023-33850
Description
IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
Affected products
18- osv-coords15 versionspkg:rpm/opensuse/java-1_8_0-ibm&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP5pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 1.8.0_sr8.20-150000.3.86.1+ 14 more
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-30.120.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-30.120.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-150000.3.86.1
- (no CPE)range: < 1.8.0_sr8.20-30.120.1
- Range: 10.1, 11.1
- Range: 11.1
- Range: 8.1, 8.2, 9.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/pages/node/7010369mitrevendor-advisory
- www.ibm.com/support/pages/node/7022413mitrevendor-advisory
- www.ibm.com/support/pages/node/7022414mitrevendor-advisory
News mentions
0No linked articles in our index yet.