Our website uses cookies to enhance your browsing experience.
Accept
to the top
>
>
>
V5343. OWASP. A cryptographically...
menu mobile close menu
Analyzing projects
Additional information
toggle menu Contents

V5343. OWASP. A cryptographically weak random number is used for sensitive data.

Sep 29 2026

The analyzer has detected that potentially sensitive data is being processed using values from an insecure random number generator.

This vulnerability type falls under the following OWASP Top 10 categories:

The example:

Random random = new Random();
long token = random.nextLong() & Long.MAX_VALUE;
HttpCookie cookie = new HttpCookie("token", Long.toString(token)); // <=

This example shows how a token is generated that can be used to save and restore a user's session. It is created using a standard pseudorandom number generator, which operates in a predictable way. If a server uses the token as an access key for a specific resource or action, an attacker can analyze received tokens, predict the next value, and gain access to another user's session and privileges.

This potential vulnerability can be fixed by using a cryptographically secure random number generator:

SecureRandom secureRandom = new SecureRandom();
long token = secureRandom.nextLong() & Long.MAX_VALUE;
HttpCookie cookie = new HttpCookie("token", Long.toString(token));

Built-in features provided by the frameworks you work with should also be used, as they eliminate the need to generate such tokens manually.

This diagnostic rule is classified as: