CVE-2023-33855: IBM Common Cryptographic Architecture

Low severity, CVSS 3.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: 257676.

Affected products

  • IBM Common Cryptographic Architecture: from 7.0.0, before 7.5.37 (fixed in 7.5.37)

Published 2024-03-26. Last modified 2026-06-17.