First published: Tue Mar 05 2019(Updated: )
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Java Software Development Kit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0729 has a severity rating that indicates a potential for Elevation of Privilege attacks.
To fix CVE-2019-0729, update to the latest version of the Azure IoT Java SDK that addresses this vulnerability.
CVE-2019-0729 could allow attackers to predict encryption keys, potentially compromising sensitive data.
If your application uses an affected version of the Azure IoT Java SDK, it is at risk from CVE-2019-0729.
Regularly update your software libraries and monitor security advisories for vulnerabilities like CVE-2019-0729.