CVE-2014-3068

IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and before 5.0 SR16 FP7 (5.0.16.7) allows attackers to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
ibmjava
5.0.0.0
ibmjava
5.0.11.0
ibmjava
5.0.11.1
ibmjava
5.0.11.2
ibmjava
5.0.12.0
ibmjava
5.0.12.1
ibmjava
5.0.12.2
ibmjava
5.0.12.3
ibmjava
5.0.12.4
ibmjava
5.0.12.5
ibmjava
5.0.13.0
ibmjava
5.0.14.0
ibmjava
5.0.15.0
ibmjava
5.0.16.0
ibmjava
5.0.16.1
ibmjava
5.0.16.2
ibmjava
5.0.16.3
ibmjava
6.0.0.0
ibmjava
6.0.1.0
ibmjava
6.0.2.0
ibmjava
6.0.3.0
ibmjava
6.0.4.0
ibmjava
6.0.5.0
ibmjava
6.0.6.0
ibmjava
6.0.7.0
ibmjava
6.0.8.0
ibmjava
6.0.8.1
ibmjava
6.0.9.0
ibmjava
6.0.9.1
ibmjava
6.0.9.2
ibmjava
6.0.10.0
ibmjava
6.0.10.1
ibmjava
6.0.11.0
ibmjava
6.0.12.0
ibmjava
6.0.13.0
ibmjava
6.0.13.1
ibmjava
6.0.13.2
ibmjava
6.0.14.0
ibmjava
7.0.0.0
ibmjava
7.0.1.0
ibmjava
7.0.2.0
ibmjava
7.0.3.0
ibmjava
7.0.4.0
ibmjava
7.0.4.1
ibmjava
7.0.4.2
ibmjava
7.0.5.0
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.5.0-ibm
RHEL 6
1:1.5.0.16.7-1jpp.1.el6_5
fixed
java-1.5.0-ibm-demo
RHEL 6
1:1.5.0.16.7-1jpp.1.el6_5
fixed
java-1.5.0-ibm-devel
RHEL 6
1:1.5.0.16.7-1jpp.1.el6_5
fixed
java-1.5.0-ibm-javacomm
RHEL 6
1:1.5.0.16.7-1jpp.1.el6_5
fixed
java-1.5.0-ibm-jdbc
RHEL 6
1:1.5.0.16.7-1jpp.1.el6_5
fixed
java-1.5.0-ibm-plugin
RHEL 6
1:1.5.0.16.7-1jpp.1.el6_5
fixed
java-1.5.0-ibm-src
RHEL 6
1:1.5.0.16.7-1jpp.1.el6_5
fixed
java-1.6.0-ibm
RHEL 6
1:1.6.0.16.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-demo
RHEL 6
1:1.6.0.16.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-devel
RHEL 6
1:1.6.0.16.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-javacomm
RHEL 6
1:1.6.0.16.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-jdbc
RHEL 6
1:1.6.0.16.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-plugin
RHEL 6
1:1.6.0.16.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-src
RHEL 6
1:1.6.0.16.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm
RHEL 6
1:1.7.0.7.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-demo
RHEL 6
1:1.7.0.7.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-devel
RHEL 6
1:1.7.0.7.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-jdbc
RHEL 6
1:1.7.0.7.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-plugin
RHEL 6
1:1.7.0.7.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-src
RHEL 6
1:1.7.0.7.1-1jpp.1.el6_5
fixed
java-1.7.1-ibm
RHEL 7
1:1.7.1.1.1-1jpp.1.el7_0
fixed
java-1.7.1-ibm-demo
RHEL 7
1:1.7.1.1.1-1jpp.1.el7_0
fixed
java-1.7.1-ibm-devel
RHEL 7
1:1.7.1.1.1-1jpp.1.el7_0
fixed
java-1.7.1-ibm-jdbc
RHEL 7
1:1.7.1.1.1-1jpp.1.el7_0
fixed
java-1.7.1-ibm-plugin
RHEL 7
1:1.7.1.1.1-1jpp.1.el7_0
fixed
java-1.7.1-ibm-src
RHEL 7
1:1.7.1.1.1-1jpp.1.el7_0
fixed
Common Weakness Enumeration