...
Predictable random number sequences can weaken the security of critical applications such as cryptography.
Rule | Severity | Likelihood | Detectable | RepairableRemediation Cost | Priority | Level |
|---|---|---|---|---|---|---|
MSC02-J | High | Probable | No | MediumNo | P12P6 | L1L2 |
Automated Detection
Tool | Version | Checker | Description | ||||||
|---|---|---|---|---|---|---|---|---|---|
| CodeSonar |
| JAVA.HARDCODED.SEED | Hardcoded Random Seed | ||||||
| Coverity | 7.5 | RISKY_CRYPTO | Implemented | ||||||
| Parasoft Jtest |
| SECURITYCRT.WSCMSC02.SRD | Use 'java.security.SecureRandom' instead of 'java.util.Random' or 'Math.random()' | ||||||
| SonarQube |
| S2245 |
...