VDB

CVE-2014-0878

CVE-2014-0878 PUBLISHED

Reported by ibm · Published May 26, 2014

The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, n/a

Timeline

  • May 26, 2014 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 25, 2023 EPSS Score

References

  • 59022 third-party-advisoryx_refsource_SECUNIA
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
  • 59058 third-party-advisoryx_refsource_SECUNIA
  • 61264 third-party-advisoryx_refsource_SECUNIA
  • ibm-java-cve20140878-weak-sec(91084) vdb-entryx_refsource_XF
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
  • 59023 third-party-advisoryx_refsource_SECUNIA
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
  • 67601 vdb-entryx_refsource_BID
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM

…and 2 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›