6.4
CVSSv2

CVE-2014-3068

Published: 02/12/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and prior to 5.0 SR16 FP7 (5.0.16.7) allows malicious users to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm java 7.0.0.0

ibm java 7.0.1.0

ibm java 6.0.9.2

ibm java 6.0.9.1

ibm java 7.0.4.2

ibm java 7.0.5.0

ibm java 6.0.6.0

ibm java 6.0.5.0

ibm java 6.0.13.0

ibm java 6.0.12.0

ibm java 6.0.11.0

ibm java 5.0.16.1

ibm java 5.0.16.0

ibm java 5.0.12.2

ibm java 5.0.12.1

ibm java 7.0.2.0

ibm java 7.0.3.0

ibm java 6.0.9.0

ibm java 6.0.8.1

ibm java 6.0.2.0

ibm java 6.0.14.0

ibm java 6.0.1.0

ibm java 6.0.0.0

ibm java 5.0.13.0

ibm java 5.0.12.5

ibm java 5.0.11.1

ibm java 5.0.11.0

ibm java 6.0.4.0

ibm java 6.0.3.0

ibm java 6.0.10.1

ibm java 6.0.10.0

ibm java 5.0.15.0

ibm java 5.0.14.0

ibm java 5.0.12.0

ibm java 5.0.11.2

ibm java 7.0.4.0

ibm java 7.0.4.1

ibm java 6.0.8.0

ibm java 6.0.7.0

ibm java 6.0.13.2

ibm java 6.0.13.1

ibm java 5.0.16.3

ibm java 5.0.16.2

ibm java 5.0.12.4

ibm java 5.0.12.3

ibm java 5.0.0.0

Vendor Advisories

Synopsis Low: Red Hat Satellite IBM Java Runtime security update Type/Severity Security Advisory: Low Topic Updated java-160-ibm packages that fix several security issues are nowavailable for Red Hat Satellite 56Red Hat Product Security has rated this update as having Low securityimpact Common Vulnerab ...
IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7111), 7 before SR7 FP1 (7071), 6 R1 before SR8 FP1 (6181), 6 before SR16 FP1 (60161), and before 50 SR16 FP7 (50167) allows attackers to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack ...

Github Repositories

A tool that checks installed packages and versions against the National Vulnerability Database (NVD)

Vulnerability-Check A tool that checks installed packages and versions against the National Vulnerability Database (NVD) and outputs the resulting vulnerabilities as a csv file Prerequisities Install the dependencies using the requirementstxt file, run: pip install -r requirementstxt Installation Clone the git repository using: git clo