CVE-2024-22340: IBM Common Cryptographic Architecture
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack.
Affected products
- IBM Common Cryptographic Architecture: from 7.0.0, before 7.5.52 (fixed in 7.5.52)
Published 2025-03-11. Last modified 2026-06-17.