PT-2023-6741 · Ibm+3 · Jsse+5

CVE-2023-30441

·

Publicado

2022-09-29

·

Atualizado

2023-06-13

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE versions 8.0.7.0 through 8.0.7.11
Description The issue is related to the use of flawed cryptographic algorithms in the Java Secure Socket Extension (JSSE) and IBMJCEPlus components. This could allow a remote attacker to gain unauthorized access to protected information. The combination of flaws and configurations in the affected components may expose sensitive information.
Recommendations For versions 8.0.7.0 through 8.0.7.11, consider updating to a version that addresses the issue with the flawed cryptographic algorithms. As a temporary workaround, restrict the use of the JSSE and IBMJCEPlus components to minimize the risk of exploitation. Avoid using the affected components for sensitive information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07522
CESA-2022_6735
CVE-2023-30441
RHSA-2022:6735
RHSA-2022:6756
RHSA-2022_6735
RHSA-2022_6756
SUSE-SU-2023:2476-1
SUSE-SU-2023:2491-1

Produtos afetados

Centos
Ibm Runtime Environment Java Technology Edition
Ibmjceplus
Jsse
Red Hat
Suse