PT-2014-3915 · Ibm+2 · Ibm Sdk Java Technology Edition+3

Amit Sethi

·

Publicado

2014-05-13

·

Atualizado

2017-08-29

·

CVE-2014-0878

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6 IBM SDK Java Technology Edition 6 before Service Refresh 16 IBM SDK Java Technology Edition 6.0.1 before Service Refresh 8 IBM SDK Java Technology Edition 7 before Service Refresh 7 IBM SDK Java Technology Edition 7R1 before Service Refresh 1
Description The issue makes it easier for attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output. This is due to a problem in the IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers.
Recommendations For IBM SDK Java Technology Edition 5.0, update to Service Refresh 16 FP6 or later. For IBM SDK Java Technology Edition 6, update to Service Refresh 16 or later. For IBM SDK Java Technology Edition 6.0.1, update to Service Refresh 8 or later. For IBM SDK Java Technology Edition 7, update to Service Refresh 7 or later. For IBM SDK Java Technology Edition 7R1, update to Service Refresh 1 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0878
RHSA-2014:0486
RHSA-2014:0508
RHSA-2014:0509
RHSA-2014:0705
RHSA-2014:0982
RHSA-2014_0486
RHSA-2014_0508
RHSA-2014_0509
RHSA-2014_0705

Produtos afetados

Ibm Aix
Ibm Sdk Java Technology Edition
Red Hat
Suse