Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: 257676.
2024-03-26T14:15:07.903
2025-07-25T21:09:49.733
Analyzed
CVSSv3.1: 3.7 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ibm | common_cryptographic_architecture | < 7.5.37 | Yes |
| Operating System | ibm | aix | - | No |
| Operating System | ibm | i | - | No |
| Operating System | linux | linux_kernel | - | No |