PT-2014-3915 · Ibm+2 · Ibm Sdk Java Technology Edition+3
Amit Sethi
·
Publicado
2014-05-13
·
Atualizado
2017-08-29
·
CVE-2014-0878
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6
IBM SDK Java Technology Edition 6 before Service Refresh 16
IBM SDK Java Technology Edition 6.0.1 before Service Refresh 8
IBM SDK Java Technology Edition 7 before Service Refresh 7
IBM SDK Java Technology Edition 7R1 before Service Refresh 1
Description
The issue makes it easier for attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output. This is due to a problem in the IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers.
Recommendations
For IBM SDK Java Technology Edition 5.0, update to Service Refresh 16 FP6 or later.
For IBM SDK Java Technology Edition 6, update to Service Refresh 16 or later.
For IBM SDK Java Technology Edition 6.0.1, update to Service Refresh 8 or later.
For IBM SDK Java Technology Edition 7, update to Service Refresh 7 or later.
For IBM SDK Java Technology Edition 7R1, update to Service Refresh 1 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Aix
Ibm Sdk Java Technology Edition
Red Hat
Suse