CVE-2014-3068

IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and before 5.0 SR16 FP7 (5.0.16.7) allows attackers to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
VendorProductVersion
ibmjava
5.0.0.0
ibmjava
5.0.11.0
ibmjava
5.0.11.1
ibmjava
5.0.11.2
ibmjava
5.0.12.0
ibmjava
5.0.12.1
ibmjava
5.0.12.2
ibmjava
5.0.12.3
ibmjava
5.0.12.4
ibmjava
5.0.12.5
ibmjava
5.0.13.0
ibmjava
5.0.14.0
ibmjava
5.0.15.0
ibmjava
5.0.16.0
ibmjava
5.0.16.1
ibmjava
5.0.16.2
ibmjava
5.0.16.3
ibmjava
6.0.0.0
ibmjava
6.0.1.0
ibmjava
6.0.2.0
ibmjava
6.0.3.0
ibmjava
6.0.4.0
ibmjava
6.0.5.0
ibmjava
6.0.6.0
ibmjava
6.0.7.0
ibmjava
6.0.8.0
ibmjava
6.0.8.1
ibmjava
6.0.9.0
ibmjava
6.0.9.1
ibmjava
6.0.9.2
ibmjava
6.0.10.0
ibmjava
6.0.10.1
ibmjava
6.0.11.0
ibmjava
6.0.12.0
ibmjava
6.0.13.0
ibmjava
6.0.13.1
ibmjava
6.0.13.2
ibmjava
6.0.14.0
ibmjava
7.0.0.0
ibmjava
7.0.1.0
ibmjava
7.0.2.0
ibmjava
7.0.3.0
ibmjava
7.0.4.0
ibmjava
7.0.4.1
ibmjava
7.0.4.2
ibmjava
7.0.5.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration