SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0878

The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and…

MEDIUM 5.8EPSS 2.09%

Does this matter?

Lower severity and a low EPSS score (2.09%). Track it; it rarely justifies an emergency change on its own.

Description

The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
2.09% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
ibm/java sdk
Source
psirt@us.ibm.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.