Cryptographic Issues Affecting java-1.7.1-ibm-demo package, versions <1:1.7.1.1.0-1jpp.2.el7_0


Severity

Recommended
critical

Based on CentOS security rating.

Threat Intelligence

EPSS
2.09% (80th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS7-JAVA171IBMDEMO-2033547
  • published26 Jul 2021
  • disclosed12 May 2014

Introduced: 12 May 2014

CVE-2014-0878  (opens in a new tab)
CWE-310  (opens in a new tab)

How to fix?

Upgrade Centos:7 java-1.7.1-ibm-demo to version 1:1.7.1.1.0-1jpp.2.el7_0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream java-1.7.1-ibm-demo package and not the java-1.7.1-ibm-demo package as distributed by Centos. See How to fix? for Centos:7 relevant fixed versions and status.

The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.

CVSS Base Scores

version 3.1