cbcvebase.
CVE-2014-0878
published 2014-05-26

CVE-2014-0878: The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6…

PriorityP426medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.09%
79.5th percentile
The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.

Affected

53 ranges· showing 25
VendorProductVersion rangeFixed in
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk
ibmjava_sdk

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.