First published: Sat Jul 02 2016(Updated: )
The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Watson Developer Cloud | ||
IBM Bluemix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0391 is classified as a medium severity vulnerability due to its potential impact on cryptographic protections.
Mitigation for CVE-2016-0391 involves ensuring that random number generation mechanisms are securely implemented in your applications using IBM Watson services.
CVE-2016-0391 allows remote attackers to perform brute-force attacks on service-instance credentials, potentially compromising security.
IBM has provided guidelines for developers to follow to enhance randomness in credential generation to mitigate CVE-2016-0391.
Users of the IBM Watson Developer Cloud services on Bluemix platforms are directly affected by CVE-2016-0391.