PT-2023-6741 · Ibm+3 · Jsse+5
Published
2022-09-29
·
Updated
2023-06-13
·
CVE-2023-30441
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE versions 8.0.7.0 through 8.0.7.11
Description
The issue is related to the use of flawed cryptographic algorithms in the Java Secure Socket Extension (JSSE) and IBMJCEPlus components. This could allow a remote attacker to gain unauthorized access to protected information. The combination of flaws and configurations in the affected components may expose sensitive information.
Recommendations
For versions 8.0.7.0 through 8.0.7.11, consider updating to a version that addresses the issue with the flawed cryptographic algorithms. As a temporary workaround, restrict the use of the JSSE and IBMJCEPlus components to minimize the risk of exploitation. Avoid using the affected components for sensitive information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Ibm Runtime Environment Java Technology Edition
Ibmjceplus
Jsse
Red Hat
Suse