Vulnerability Bulletins

IBM Security Bulletin: node-uuid unsafe fallback to Math.random (CVE-2015-8851)

   
Affected software IBM
 
A vulnerability in the node-uuid module causes the module to fallback on math.random under certain circumstances, which leads to predictable UUIDs. The node-uuid module is used by the Node.js Package Manager (npm).CVE(s): CVE-2015-8851Affected product(s) and affected version(s):IBM Rational Application Developer for WebSphere Software v9.1 and v9.5 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_node_uuid_unsafe_fallback_to_math_random_cve_2015_8851?lang=en_us