Inadequate Encryption Strength in IBM HTTP Server - CVE-2023-32342
Published: May 24, 2023
Vulnerability identifier: #VU76487
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32342
CWE-ID: CWE-326
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to IBM GSKit is using weak cryptographic algorithms. A remote attacker can send an overly large number of trial messages for decryption and perform a timing-based side channel attack against the RSA Decryption implementation.
Affected software
IBM HTTP Server
Informix Dynamic Server
IBM Sterling Transformation Extender
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Workload Scheduler
IBM Content Collector for SAP Applications
IBM Sterling Connect:Direct for UNIX
IBM Sterling B2B Integrator
IBM Tivoli Monitoring
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM MQ
IBM Security Verify Bridge for Directory Sync
IBM Planning Analytics Workspace
IBM Sterling Connect:Direct for Microsoft Windows
IBM Security Directory Server
Communications Server for AIX
Communications Server for Linux
Communications Server for Data Center Deployment on AIX
Communications Server for Data Center Deployment on Linux
IBM Security Directory Suite
Storage Protect Snapshot for UNIX and Linux
Storage Protect Server
IBM MQ Appliance
IBM Security Verify Access
IBM i Access Client Solutions
IBM DataPower Gateway
Planning Analytics Local
Informix Client Software Development Kit
IBM CICS TX Advanced
IBM CICS TX Standard
IBM DB2
Informix Dynamic Server
IBM Sterling Transformation Extender
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Workload Scheduler
IBM Content Collector for SAP Applications
IBM Sterling Connect:Direct for UNIX
IBM Sterling B2B Integrator
IBM Tivoli Monitoring
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM MQ
IBM Security Verify Bridge for Directory Sync
IBM Planning Analytics Workspace
IBM Sterling Connect:Direct for Microsoft Windows
IBM Security Directory Server
Communications Server for AIX
Communications Server for Linux
Communications Server for Data Center Deployment on AIX
Communications Server for Data Center Deployment on Linux
IBM Security Directory Suite
Storage Protect Snapshot for UNIX and Linux
Storage Protect Server
IBM MQ Appliance
IBM Security Verify Access
IBM i Access Client Solutions
IBM DataPower Gateway
Planning Analytics Local
Informix Client Software Development Kit
IBM CICS TX Advanced
IBM CICS TX Standard
IBM DB2
How to mitigate CVE-2023-32342
Install updates from vendor's website.
IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
IBM Rational ClearCase - update to 9.0.2.8
IBM Workload Scheduler - addressed in versions 10.1.0.6, 10.2.5
IBM i Access Client Solutions - update to 1.1.0.27
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Content Collector for SAP Applications - update to 4.0.0.4.0.14
Informix Client Software Development Kit - addressed in versions 4.10.FC16W1, 4.50.FC10W1
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.0.0.2.152, 6.1.0.4.88, 6.2.0.6.24, 6.3.0.0.11
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.67, 6.1.0.2.62, 6.2.0.4.36
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Security Directory Server - update to 6.4.0.28
Communications Server for AIX - update to 7.0.0.8
Communications Server for Linux - update to 7.0.0.8
Communications Server for Data Center Deployment on AIX - update to 7.1.1
Communications Server for Data Center Deployment on Linux - update to 7.1.1
IBM Security Directory Suite - update to 8.0.1.21
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
Storage Protect Snapshot for UNIX and Linux - update to 8.1.11.3
Storage Protect Server - update to 8.1.19
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
IBM MQ - addressed in versions 9.0.0.18, 9.1.0.16, 9.2.0.15, 9.3.0.6, 9.3.3
IBM MQ Appliance - addressed in versions 9.2.0.15, 9.2.5.8, 9.3.0.6, 9.3.3
IBM DataPower Gateway - addressed in versions 10.0.1.14, 10.5.0.6
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix20, 11.1.0.0 ifix12
IBM DB2 - addressed in versions 10.5 FP11, 11.1.4.7, 11.5.7, 11.5.8
IBM CICS TX Standard - update to 11.1.0.0 ifix12
Informix Dynamic Server - addressed in versions 12.10.FC16W1, 14.10.FC10W1
IBM Rational ClearCase - update to 9.0.2.8
IBM Workload Scheduler - addressed in versions 10.1.0.6, 10.2.5
IBM i Access Client Solutions - update to 1.1.0.27
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Content Collector for SAP Applications - update to 4.0.0.4.0.14
Informix Client Software Development Kit - addressed in versions 4.10.FC16W1, 4.50.FC10W1
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.0.0.2.152, 6.1.0.4.88, 6.2.0.6.24, 6.3.0.0.11
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.67, 6.1.0.2.62, 6.2.0.4.36
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Security Directory Server - update to 6.4.0.28
Communications Server for AIX - update to 7.0.0.8
Communications Server for Linux - update to 7.0.0.8
Communications Server for Data Center Deployment on AIX - update to 7.1.1
Communications Server for Data Center Deployment on Linux - update to 7.1.1
IBM Security Directory Suite - update to 8.0.1.21
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
Storage Protect Snapshot for UNIX and Linux - update to 8.1.11.3
Storage Protect Server - update to 8.1.19
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
IBM MQ - addressed in versions 9.0.0.18, 9.1.0.16, 9.2.0.15, 9.3.0.6, 9.3.3
IBM MQ Appliance - addressed in versions 9.2.0.15, 9.2.5.8, 9.3.0.6, 9.3.3
IBM DataPower Gateway - addressed in versions 10.0.1.14, 10.5.0.6
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix20, 11.1.0.0 ifix12
IBM DB2 - addressed in versions 10.5 FP11, 11.1.4.7, 11.5.7, 11.5.8
IBM CICS TX Standard - update to 11.1.0.0 ifix12
Informix Dynamic Server - addressed in versions 12.10.FC16W1, 14.10.FC10W1
External References
Related Security Bulletins
- Information disclosure in IBM HTTP Server
- Inadequate encryption strength in IBM Content Collector for SAP Applications
- Inadequate encryption strength in IBM Sterling Connect:Direct for Microsoft Windows
- Inadequate encryption strength in IBM i Access Client Solutions - Windows Application Package
- Inadequate encryption strength in IBM DataPower Gateway
- Inadequate encryption strength in IBM MQ Appliance
- Inadequate encryption strength in IBM MQ
- Inadequate encryption strength in IBM Communications Server for AIX
- Inadequate encryption strength in IBM Communications Server for Linux & CS for Linux on System z
- Inadequate encryption strength in IBM Storage Protect Client, IBM Storage Protect for Virtual Environments, and IBM Storage Protect for Space Management
- Inadequate encryption strength in IBM CICS TX Standard
- Inadequate encryption strength in IBM CICS TX Advanced
- IBM Security Verify Access update for IBM GSKit
- Inadequate encryption strength in IBM Sterling Connect:Direct for UNIX
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Inadequate encryption strength in IBM Storage Protect Snapshot for UNIX and Linux
- Inadequate encryption strength in IBM TXSeries for Multiplatforms
- Inadequate encryption strength in IBM Db2
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in IBM Sterling Transformation Extender
- Inadequate encryption strength in IBM Security Directory Server Products
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Inadequate Encryption Strength in Informix Dynamic Server
- Inadequate Encryption Strength in Informix Client Software Development Kit
- Multiple vulnerabilities in IBM Application Performance Management
- IBM Workload Scheduler update for IBM GSKit