CVE-2013-5391

MEDIUM

IBM Worklight <5.0.6.2 & <6.0.0.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.0 Fix Pack 2 make it easier for attackers to defeat cryptographic protection mechanisms by leveraging improper initialization of the pseudo random number generator (PRNG) in Android and use of the Java Cryptography Architecture (JCA) by a Worklight program. IBM X-Force ID: 87128.

References (2)

Core 2
Core References
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87128
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21665731

Scores

CVSS v3 5.3
EPSS 0.0103
EPSS Percentile 60.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-310
Status published
Products (8)
ibm/mobile_foundation 5.0.0.0 (2 CPE variants)
ibm/mobile_foundation 5.0.5.0 (2 CPE variants)
ibm/mobile_foundation 5.0.6.0 (2 CPE variants)
ibm/mobile_foundation 6.0.0.0 (2 CPE variants)
ibm/worklight 5.0.0.0 (2 CPE variants)
ibm/worklight 5.0.5.0 (2 CPE variants)
ibm/worklight 5.0.6.0 (2 CPE variants)
ibm/worklight 6.0.0.0 (2 CPE variants)
Published Apr 27, 2018
Tracked Since Feb 18, 2026