CVE-2013-5391
Last modified
CVE-2013-5391 is a vulnerability of currently unknown severity. IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.0 Fix Pack 2 make it easier for attackers to defeat cryptographic protection mechanisms by leveraging improper initialization of the pseudo random number generator (PRNG) in Android and use of the Java Cryptography Architecture (JCA) by a Worklight program. IBM X-Force ID: 87128.. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.0 Fix Pack 2 make it easier for attackers to defeat cryptographic protection mechanisms by leveraging improper initialization of the pseudo random number generator (PRNG) in Android and use of the Java Cryptography Architecture (JCA) by a Worklight program. IBM X-Force ID: 87128.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Worklight | 5.0.0.0 |
| Ibm | Worklight | 5.0.5.0 |
| Ibm | Worklight | 5.0.6.0 |
| Ibm | Worklight | 6.0.0.0 |
| Ibm | Mobile Foundation | 5.0.0.0 |
| Ibm | Mobile Foundation | 5.0.5.0 |
| Ibm | Mobile Foundation | 5.0.6.0 |
| Ibm | Mobile Foundation | 6.0.0.0 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21665731Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87128VDB Entry, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21665731Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87128VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-5391?
How severe is CVE-2013-5391?
How do I fix CVE-2013-5391?
Are you affected by CVE-2013-5391?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
