CVE-2014-0878 describes a weakness in the IBMSecureRandom component within IBM SDK Java Technology Edition versions 5.0, 6, 6.0.1, 7, and 7R1. This vulnerability allows attackers to predict the output of the random number generator, thereby weakening cryptographic protections. With a CVSS score of 5.8, this medium-severity issue can be exploited remotely with medium attack complexity, potentially leading to partial confidentiality and integrity compromise. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.0.0CPE matchmatch criteria | cpe:2.3:a:ibm:java_sdk:6.0.0.0:*:*:*:technology:*:*:* | ||
6.0.1.0CPE matchmatch criteria | cpe:2.3:a:ibm:java_sdk:6.0.1.0:*:*:*:technology:*:*:* | ||
6.0.2.0CPE matchmatch criteria | cpe:2.3:a:ibm:java_sdk:6.0.2.0:*:*:*:technology:*:*:* | ||
6.0.3.0CPE matchmatch criteria | cpe:2.3:a:ibm:java_sdk:6.0.3.0:*:*:*:technology:*:*:* | ||
6.0.4.0CPE matchmatch criteria | cpe:2.3:a:ibm:java_sdk:6.0.4.0:*:*:*:technology:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.