Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key.
https://exchange.xforce.ibmcloud.com/vulnerabilities/78771
http://www.securityfocus.com/bid/55618
http://secunia.com/advisories/50660