CVE-2023-30441Use of a Broken or Risky Cryptographic Algorithm in IBM Java

Severity
7.5HIGHNVD
EPSS
0.0%
top 84.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 29

Description

IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDibm/java8.0.7.08.0.7.15
CVEListV5ibm/java8.0.7.08.0.7.11
NVDibm/websphere_application_server8.5.0.08.5.5.23+1

🔴Vulnerability Details

2
CVEList
IBM Java information disclosure2023-04-29
GHSA
GHSA-2v8w-cv2x-fj9v: IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 82023-04-29

📋Vendor Advisories

1
Red Hat
JDK: exposure of sensitive information using a combination of flaws and configurations2023-04-20
CVE-2023-30441 — IBM Java vulnerability | cvebase