CVE-2012-2681: Red Hat Enterprise Mrg

Medium severity, CVSS 5.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key.

Affected products

  • Red Hat Enterprise Mrg: version 2.0 only
  • Trevor Mckay Cumin: up to and including 0.1.5192-4; version 0.1.3160-1 only; version 0.1.4369-1 only; version 0.1.4410-2 only; version 0.1.4494-1 only; version 0.1.4794-1 only; …

Published 2012-09-28. Last modified 2026-06-16.