Inadequate Encryption Strength in IBM HTTP Server - CVE-2023-32342

 

Inadequate Encryption Strength in IBM HTTP Server - CVE-2023-32342

Published: May 24, 2023


Vulnerability identifier: #VU76487
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32342
CWE-ID: CWE-326
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to IBM GSKit is using weak cryptographic algorithms. A remote attacker can send an overly large number of trial messages for decryption and perform a timing-based side channel attack against the RSA Decryption implementation.


Affected software

IBM HTTP Server
Informix Dynamic Server
IBM Sterling Transformation Extender
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Workload Scheduler
IBM Content Collector for SAP Applications
IBM Sterling Connect:Direct for UNIX
IBM Sterling B2B Integrator
IBM Tivoli Monitoring
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM MQ
IBM Security Verify Bridge for Directory Sync
IBM Planning Analytics Workspace
IBM Sterling Connect:Direct for Microsoft Windows
IBM Security Directory Server
Communications Server for AIX
Communications Server for Linux
Communications Server for Data Center Deployment on AIX
Communications Server for Data Center Deployment on Linux
IBM Security Directory Suite
Storage Protect Snapshot for UNIX and Linux
Storage Protect Server
IBM MQ Appliance
IBM Security Verify Access
IBM i Access Client Solutions
IBM DataPower Gateway
Planning Analytics Local
Informix Client Software Development Kit
IBM CICS TX Advanced
IBM CICS TX Standard
IBM DB2

How to mitigate CVE-2023-32342

Install updates from vendor's website.

IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
IBM Rational ClearCase - update to 9.0.2.8
IBM Workload Scheduler - addressed in versions 10.1.0.6, 10.2.5
IBM i Access Client Solutions - update to 1.1.0.27
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Content Collector for SAP Applications - update to 4.0.0.4.0.14
Informix Client Software Development Kit - addressed in versions 4.10.FC16W1, 4.50.FC10W1
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.0.0.2.152, 6.1.0.4.88, 6.2.0.6.24, 6.3.0.0.11
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.67, 6.1.0.2.62, 6.2.0.4.36
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Security Directory Server - update to 6.4.0.28
Communications Server for AIX - update to 7.0.0.8
Communications Server for Linux - update to 7.0.0.8
Communications Server for Data Center Deployment on AIX - update to 7.1.1
Communications Server for Data Center Deployment on Linux - update to 7.1.1
IBM Security Directory Suite - update to 8.0.1.21
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
Storage Protect Snapshot for UNIX and Linux - update to 8.1.11.3
Storage Protect Server - update to 8.1.19
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
IBM MQ - addressed in versions 9.0.0.18, 9.1.0.16, 9.2.0.15, 9.3.0.6, 9.3.3
IBM MQ Appliance - addressed in versions 9.2.0.15, 9.2.5.8, 9.3.0.6, 9.3.3
IBM DataPower Gateway - addressed in versions 10.0.1.14, 10.5.0.6
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix20, 11.1.0.0 ifix12
IBM DB2 - addressed in versions 10.5 FP11, 11.1.4.7, 11.5.7, 11.5.8
IBM CICS TX Standard - update to 11.1.0.0 ifix12
Informix Dynamic Server - addressed in versions 12.10.FC16W1, 14.10.FC10W1

External References

Related Security Bulletins