PT-2014-3915 · Ibm+2 · Ibm Sdk Java Technology Edition+3

Amit Sethi

·

Published

2014-05-13

·

Updated

2017-08-29

·

CVE-2014-0878

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6 IBM SDK Java Technology Edition 6 before Service Refresh 16 IBM SDK Java Technology Edition 6.0.1 before Service Refresh 8 IBM SDK Java Technology Edition 7 before Service Refresh 7 IBM SDK Java Technology Edition 7R1 before Service Refresh 1
Description The issue makes it easier for attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output. This is due to a problem in the IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers.
Recommendations For IBM SDK Java Technology Edition 5.0, update to Service Refresh 16 FP6 or later. For IBM SDK Java Technology Edition 6, update to Service Refresh 16 or later. For IBM SDK Java Technology Edition 6.0.1, update to Service Refresh 8 or later. For IBM SDK Java Technology Edition 7, update to Service Refresh 7 or later. For IBM SDK Java Technology Edition 7R1, update to Service Refresh 1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0878
RHSA-2014:0486
RHSA-2014:0508
RHSA-2014:0509
RHSA-2014:0705
RHSA-2014:0982
RHSA-2014_0486
RHSA-2014_0508
RHSA-2014_0509
RHSA-2014_0705

Affected Products

Ibm Aix
Ibm Sdk Java Technology Edition
Red Hat
Suse