﻿# V5343\. OWASP\. A cryptographically weak random number is used for sensitive data\.

The analyzer has detected that potentially sensitive data is being processed using values from an insecure random number generator\.

This vulnerability type falls under the following OWASP Top 10 categories:

* [A04:2025 Cryptographic Failures](https://owasp.org/Top10/2025/A04_2025-Cryptographic_Failures/)
* [A02:2021 – Cryptographic Failures](https://owasp.org/Top10/2021/A02_2021-Cryptographic_Failures/)

The example:

```cpp
Random random = new Random();
long token = random.nextLong() & Long.MAX_VALUE;
HttpCookie cookie = new HttpCookie("token", Long.toString(token)); // <=
```

This example shows how a token is generated that can be used to save and restore a user's session\. It is created using a standard pseudorandom number generator, which operates in a predictable way\. If a server uses the token as an access key for a specific resource or action, an attacker can analyze received tokens, predict the next value, and gain access to another user's session and privileges\. 

This potential vulnerability can be fixed by using a cryptographically secure random number generator:

```cpp
SecureRandom secureRandom = new SecureRandom();
long token = secureRandom.nextLong() & Long.MAX_VALUE;
HttpCookie cookie = new HttpCookie("token", Long.toString(token));
```

Built\-in features provided by the frameworks you work with should also be used, as they eliminate the need to generate such tokens manually\.