CVE-2014-3068: Medium severity ibm jdk vulnerability
A vulnerability was found in the Java Certificate Management System (CMS) keystore provider that could potentially allow an attacker to recover the private key from CMS keystores via a brute-force attack.
External References:
http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateJuly2014 http://www-01.ibm.com/support/docview.wss?uid=swg21680334 http://xforce.iss.net/xforce/xfdb/93756
Other sources
IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and before 5.0 SR16 FP7 (5.0.16.7) allows attackers to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3068?
CVE-2014-3068 is considered a high-severity vulnerability due to its potential to expose private keys through a brute-force attack.
How do I fix CVE-2014-3068?
To fix CVE-2014-3068, upgrade to a patched version of IBM JDK, which addresses the vulnerability.
Which versions of IBM JDK are affected by CVE-2014-3068?
CVE-2014-3068 affects multiple versions of IBM JDK, including version 5.0 through 7.0.5.0.
Can CVE-2014-3068 impact my application's security?
Yes, CVE-2014-3068 can significantly impact application security by allowing attackers to recover sensitive private keys.
Is CVE-2014-3068 related to Java security?
Yes, CVE-2014-3068 is a Java security vulnerability specifically linked to the Java Certificate Management System keystore provider.