CVE-2014-0878
Detail
Deferred
This CVE record is not being prioritized for NVD enrichment efforts due to resource or other concerns.
Description
The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 2.0 Severity and Vector Strings:
Vector:
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
URL
Source(s)
Tag(s)
http://secunia.com/advisories/59022
CVE, IBM Corporation
http://secunia.com/advisories/59023
CVE, IBM Corporation
http://secunia.com/advisories/59058
CVE, IBM Corporation
http://secunia.com/advisories/61264
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21672043
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21673836
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21674539
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21676672
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21676703
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21676746
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21679610
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21679713
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21680750
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21681256
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21683484
CVE, IBM Corporation
http://www-01.ibm.com/support/docview.wss?uid=swg21686717
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21689593
CVE, IBM Corporation
Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=swg21675343
CVE, IBM Corporation
http://www.ibm.com/support/docview.wss?uid=swg21675588
CVE, IBM Corporation
http://www.ibm.com/support/docview.wss?uid=swg21677387
CVE, IBM Corporation
http://www.securityfocus.com/bid/67601
CVE, IBM Corporation
https://exchange.xforce.ibmcloud.com/vulnerabilities/91084
CVE, IBM Corporation
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-310
Cryptographic Issues
NIST
Change History
8 change records found show changes
CVE Modified by CVE 11/20/2024 9:02:57 PM
Action
Type
Old Value
New Value
Added
Reference
http://secunia.com/advisories/59022
Added
Reference
http://secunia.com/advisories/59023
Added
Reference
http://secunia.com/advisories/59058
Added
Reference
http://secunia.com/advisories/61264
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21672043
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21673836
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21674539
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21676672
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21676703
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21676746
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21679610
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21679713
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21680750
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21681256
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21683484
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21686717
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21689593
Added
Reference
http://www.ibm.com/support/docview.wss?uid=swg21675343
Added
Reference
http://www.ibm.com/support/docview.wss?uid=swg21675588
Added
Reference
http://www.ibm.com/support/docview.wss?uid=swg21677387
Added
Reference
http://www.securityfocus.com/bid/67601
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/91084
CVE Modified by IBM Corporation 5/13/2024 11:08:24 PM
Action
Type
Old Value
New Value
CVE Modified by IBM Corporation 8/28/2017 9:34:18 PM
Action
Type
Old Value
New Value
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/91084 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/91084 [No Types Assigned]
CVE Modified by IBM Corporation 1/06/2017 9:59:34 PM
Action
Type
Old Value
New Value
Added
Reference
http://secunia.com/advisories/61264 [No Types Assigned]
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21676672 [No Types Assigned]
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21679610 [No Types Assigned]
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21680750 [No Types Assigned]
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21683484 [No Types Assigned]
Modified Analysis by NIST 1/02/2015 9:05:12 PM
Action
Type
Old Value
New Value
Changed
CPE Configuration
Record truncated, showing 2048 of 3544 characters.
View Entire Change Record
Configuration 1
OR
*cpe:2.3:a:ibm:java_sdk:7.1.0.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.0.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.1.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.2.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.3.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.4.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.4.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.4.2:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.5.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.6.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:7.0.6.1:*:*:*:technology:*:*:*
Configuration 2
OR
*cpe:2.3:a:ibm:java_sdk:5.0.0.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.11.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.11.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.11.2:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.12.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.12.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.12.2:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.12.3:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.12.4:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.12.5:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.13.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.14.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.15.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.16.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.16.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.16.2:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.16.3:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.16.4:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.16.5:*:*:*:technology:*:*:*
Configuration 3
OR
Record truncated, showing 2048 of 3544 characters.
View Entire Change Record
Configuration 1
OR
*cpe:2.3:a:ibm:java_sdk:6.0.0.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.1.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.2.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.3.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.4.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.5.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.6.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.7.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.8.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.8.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.9.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.9.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.9.2:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.10.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.10.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.11.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.12.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.13.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.13.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.13.2:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.14.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.15.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:6.0.15.1:*:*:*:technology:*:*:*
Configuration 2
OR
*cpe:2.3:a:ibm:java_sdk:5.0.0.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.11.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.11.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.11.2:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.12.0:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.12.1:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:5.0.12.2:*:*:*:technology:*:*:*
*cpe:2.3:a:ibm:java_sdk:
Changed
Reference Type
http://www-01.ibm.com/support/docview.wss?uid=swg21686717 No Types Assigned
http://www-01.ibm.com/support/docview.wss?uid=swg21686717 Advisory
Changed
Reference Type
http://www-01.ibm.com/support/docview.wss?uid=swg21689593 No Types Assigned
http://www-01.ibm.com/support/docview.wss?uid=swg21689593 Advisory
CVE Modified by IBM Corporation 12/23/2014 9:59:19 PM
Action
Type
Old Value
New Value
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21689593
CVE Modified by IBM Corporation 11/18/2014 9:59:54 PM
Action
Type
Old Value
New Value
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21686717
Initial CVE Analysis 5/27/2014 3:40:04 PM
Action
Type
Old Value
New Value
Quick Info
CVE Dictionary Entry: CVE-2014-0878 NVD
Published Date: 05/26/2014 NVD
Last Modified: 04/12/2025
Source: IBM Corporation