[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0878Date: (C)2014-05-28   (M)2023-12-28


The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.8
Exploit Score: 8.6
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-59022
SECUNIA-59023
SECUNIA-59058
SECUNIA-61264
BID-67601
http://www-01.ibm.com/support/docview.wss?uid=swg21672043
http://www-01.ibm.com/support/docview.wss?uid=swg21673836
http://www-01.ibm.com/support/docview.wss?uid=swg21674539
http://www-01.ibm.com/support/docview.wss?uid=swg21676672
http://www-01.ibm.com/support/docview.wss?uid=swg21676703
http://www-01.ibm.com/support/docview.wss?uid=swg21676746
http://www-01.ibm.com/support/docview.wss?uid=swg21679610
http://www-01.ibm.com/support/docview.wss?uid=swg21679713
http://www-01.ibm.com/support/docview.wss?uid=swg21680750
http://www-01.ibm.com/support/docview.wss?uid=swg21681256
http://www-01.ibm.com/support/docview.wss?uid=swg21683484
http://www-01.ibm.com/support/docview.wss?uid=swg21686717
http://www-01.ibm.com/support/docview.wss?uid=swg21689593
http://www.ibm.com/support/docview.wss?uid=swg21675343
http://www.ibm.com/support/docview.wss?uid=swg21675588
http://www.ibm.com/support/docview.wss?uid=swg21677387
ibm-java-cve20140878-weak-sec(91084)

CPE    53
cpe:/a:ibm:java_sdk:5.0.12.5::~~technology~~~
cpe:/a:ibm:java_sdk:5.0.15.0::~~technology~~~
cpe:/a:ibm:java_sdk:5.0.13.0::~~technology~~~
cpe:/a:ibm:java_sdk:5.0.12.4::~~technology~~~
...
CWE    1
CWE-310
OVAL    6
oval:org.secpod.oval:def:21291
oval:org.secpod.oval:def:505652
oval:org.secpod.oval:def:505656
oval:org.secpod.oval:def:505264
...

© SecPod Technologies