CVE-2013-5391
MEDIUMIBM Worklight <5.0.6.2 & <6.0.0.2 - Privilege Escalation
Title source: llmDescription
IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.0 Fix Pack 2 make it easier for attackers to defeat cryptographic protection mechanisms by leveraging improper initialization of the pseudo random number generator (PRNG) in Android and use of the Java Cryptography Architecture (JCA) by a Worklight program. IBM X-Force ID: 87128.
References (2)
Core 2
Core References
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87128
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21665731
Scores
CVSS v3
5.3
EPSS
0.0103
EPSS Percentile
60.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-310
Status
published
Products (8)
ibm/mobile_foundation
5.0.0.0 (2 CPE variants)
ibm/mobile_foundation
5.0.5.0 (2 CPE variants)
ibm/mobile_foundation
5.0.6.0 (2 CPE variants)
ibm/mobile_foundation
6.0.0.0 (2 CPE variants)
ibm/worklight
5.0.0.0 (2 CPE variants)
ibm/worklight
5.0.5.0 (2 CPE variants)
ibm/worklight
5.0.6.0 (2 CPE variants)
ibm/worklight
6.0.0.0 (2 CPE variants)
Published
Apr 27, 2018
Tracked Since
Feb 18, 2026