CVE-2023-33850: IBM Cics Tx

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.

Affected products

  • IBM Cics Tx: version 11.1 only; version 10.1 only
  • IBM Txseries For Multiplatform: version 8.1 only; version 9.1 only; version 8.2 only

Published 2023-08-22. Last modified 2026-06-17.