SB2022090510 - Information disclosure in IBM Watson Machine Learning Accelerator
Published: September 5, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2020-15522)
The vulnerability allows a remote attacker to gain access to sensitive information.
The
vulnerability exists due to a timing issue within the EC math library. A remote attacker who can observe timing information for the generation of multiple deterministic ECDSA signatures is able to reconstruct the private key used for encryption.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-bouncy-castle-affect-ibm-watson-machine-learning-accelerator-2/"
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-bouncy-castle-affect-ibm-watson-machine-learning-accelerator-2/</a><br>
- https://www.ibm.com/support/pages/node/6485147<br></p>