PT-2024-29549 · Ibm · Ibm Txseries For Multiplatforms
Published
2024-11-01
·
Updated
2024-11-15
·
CVE-2024-41741
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM TXSeries for Multiplatforms version 10.1
Description
The issue allows an attacker to determine valid usernames due to an observable timing discrepancy, which could be used in further attacks against the system.
Recommendations
For IBM TXSeries for Multiplatforms version 10.1, consider implementing measures to mitigate the observable timing discrepancy, such as introducing random delays or masking the timing differences in authentication responses. As a temporary workaround, consider restricting access to sensitive areas of the system that rely on username authentication until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Txseries For Multiplatforms