CVE-2014-0878
published 2014-05-26CVE-2014-0878: The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6…
PriorityP426medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.09%
79.5th percentile
The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
| ibm | java_sdk | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5qx-wfhq-jh75: The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5
ghsa_unreviewed·2022-05-17
CVE-2014-0878 [MEDIUM] GHSA-v5qx-wfhq-jh75: The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5
The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.
Red Hat
JDK: Vulnerability in the IBMSecureRandom implementation of the IBMJCE and IBMSecureRandom cryptographic providers
vendor_redhat·2014-05-12·CVSS 5.8
CVE-2014-0878 [MEDIUM] JDK: Vulnerability in the IBMSecureRandom implementation of the IBMJCE and IBMSecureRandom cryptographic providers
JDK: Vulnerability in the IBMSecureRandom implementation of the IBMJCE and IBMSecureRandom cryptographic providers
The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/59022http://secunia.com/advisories/59023http://secunia.com/advisories/59058http://secunia.com/advisories/61264http://www-01.ibm.com/support/docview.wss?uid=swg21672043http://www-01.ibm.com/support/docview.wss?uid=swg21673836http://www-01.ibm.com/support/docview.wss?uid=swg21674539http://www-01.ibm.com/support/docview.wss?uid=swg21676672http://www-01.ibm.com/support/docview.wss?uid=swg21676703http://www-01.ibm.com/support/docview.wss?uid=swg21676746http://www-01.ibm.com/support/docview.wss?uid=swg21679610http://www-01.ibm.com/support/docview.wss?uid=swg21679713http://www-01.ibm.com/support/docview.wss?uid=swg21680750http://www-01.ibm.com/support/docview.wss?uid=swg21681256http://www-01.ibm.com/support/docview.wss?uid=swg21683484http://www-01.ibm.com/support/docview.wss?uid=swg21686717http://www-01.ibm.com/support/docview.wss?uid=swg21689593http://www.ibm.com/support/docview.wss?uid=swg21675343http://www.ibm.com/support/docview.wss?uid=swg21675588http://www.ibm.com/support/docview.wss?uid=swg21677387http://www.securityfocus.com/bid/67601https://exchange.xforce.ibmcloud.com/vulnerabilities/91084http://secunia.com/advisories/59022http://secunia.com/advisories/59023http://secunia.com/advisories/59058http://secunia.com/advisories/61264http://www-01.ibm.com/support/docview.wss?uid=swg21672043http://www-01.ibm.com/support/docview.wss?uid=swg21673836http://www-01.ibm.com/support/docview.wss?uid=swg21674539http://www-01.ibm.com/support/docview.wss?uid=swg21676672http://www-01.ibm.com/support/docview.wss?uid=swg21676703http://www-01.ibm.com/support/docview.wss?uid=swg21676746http://www-01.ibm.com/support/docview.wss?uid=swg21679610http://www-01.ibm.com/support/docview.wss?uid=swg21679713http://www-01.ibm.com/support/docview.wss?uid=swg21680750http://www-01.ibm.com/support/docview.wss?uid=swg21681256http://www-01.ibm.com/support/docview.wss?uid=swg21683484http://www-01.ibm.com/support/docview.wss?uid=swg21686717http://www-01.ibm.com/support/docview.wss?uid=swg21689593http://www.ibm.com/support/docview.wss?uid=swg21675343http://www.ibm.com/support/docview.wss?uid=swg21675588http://www.ibm.com/support/docview.wss?uid=swg21677387http://www.securityfocus.com/bid/67601https://exchange.xforce.ibmcloud.com/vulnerabilities/91084
2014-05-26
Published