CVE-2024-22340: IBM Common Cryptographic Architecture

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack.

Affected products

  • IBM Common Cryptographic Architecture: from 7.0.0, before 7.5.52 (fixed in 7.5.52)

Published 2025-03-11. Last modified 2026-06-17.