PT-2023-6741 · Ibm+3 · Jsse+5

Published

2022-09-29

·

Updated

2023-06-13

·

CVE-2023-30441

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE versions 8.0.7.0 through 8.0.7.11
Description The issue is related to the use of flawed cryptographic algorithms in the Java Secure Socket Extension (JSSE) and IBMJCEPlus components. This could allow a remote attacker to gain unauthorized access to protected information. The combination of flaws and configurations in the affected components may expose sensitive information.
Recommendations For versions 8.0.7.0 through 8.0.7.11, consider updating to a version that addresses the issue with the flawed cryptographic algorithms. As a temporary workaround, restrict the use of the JSSE and IBMJCEPlus components to minimize the risk of exploitation. Avoid using the affected components for sensitive information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

BDU:2023-07522
CESA-2022_6735
CVE-2023-30441
RHSA-2022:6735
RHSA-2022:6756
RHSA-2022_6735
RHSA-2022_6756
SUSE-SU-2023:2476-1
SUSE-SU-2023:2491-1

Affected Products

Centos
Ibm Runtime Environment Java Technology Edition
Ibmjceplus
Jsse
Red Hat
Suse