Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: 257676.
Covert timing channels convey information by modulating some aspect of system behavior over time, so that the program receiving the information can observe system behavior and infer protected information.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7145168 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/257676 | vdb entry third party advisory |