PT-2014-3915 · Ibm+2 · Ibm Sdk Java Technology Edition+3
Amit Sethi
·
Published
2014-05-13
·
Updated
2017-08-29
·
CVE-2014-0878
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6
IBM SDK Java Technology Edition 6 before Service Refresh 16
IBM SDK Java Technology Edition 6.0.1 before Service Refresh 8
IBM SDK Java Technology Edition 7 before Service Refresh 7
IBM SDK Java Technology Edition 7R1 before Service Refresh 1
Description
The issue makes it easier for attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output. This is due to a problem in the IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers.
Recommendations
For IBM SDK Java Technology Edition 5.0, update to Service Refresh 16 FP6 or later.
For IBM SDK Java Technology Edition 6, update to Service Refresh 16 or later.
For IBM SDK Java Technology Edition 6.0.1, update to Service Refresh 8 or later.
For IBM SDK Java Technology Edition 7, update to Service Refresh 7 or later.
For IBM SDK Java Technology Edition 7R1, update to Service Refresh 1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Aix
Ibm Sdk Java Technology Edition
Red Hat
Suse