CVE-2003-1229
Last modified
CVE-2003-1229 is a vulnerability of currently unknown severity. X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.. EPSS estimates a 4.63% chance of exploitation in the next 30 days.
Description
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Jre | >= 1.3.0, <= 1.4.1 |
| Sun | Java Web Start | >= 1.0, <= 1.2 |
| Sun | Jsse | 1.0.3 |
References
- http://java.sun.com/products/jsse/CHANGES.txtBroken Link, Vendor Advisory
- http://secunia.com/advisories/7943Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1006007Broken Link, Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1007483Broken Link, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-50081-1Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/6682Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1006001Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11182Third Party Advisory, VDB Entry
- http://java.sun.com/products/jsse/CHANGES.txtBroken Link, Vendor Advisory
- http://secunia.com/advisories/7943Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1006007Broken Link, Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1007483Broken Link, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-50081-1Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/6682Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1006001Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11182Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1229?
How severe is CVE-2003-1229?
How do I fix CVE-2003-1229?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-1223The Node Manager for BEA WebLogic Express and Server 6.1 thr…
- CVE-2003-1224Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7…
- CVE-2003-1225The default CredentialMapper for BEA WebLogic Server and Exp…
- CVE-2003-1226BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certa…
- CVE-2003-1227PHP remote file include vulnerability in index.php for Galle…
- CVE-2003-1228Buffer overflow in the prepare_reply function in request.c f…
- CVE-2003-1230The implementation of SYN cookies (syncookies) in FreeBSD 4.…
- CVE-2003-1231Cross-site scripting (XSS) vulnerability in index.php in ECW…
- CVE-2003-1232Emacs 21.2.1 does not prompt or warn the user before executi…
- CVE-2003-1233Pedestal Software Integrity Protection Driver (IPD) 1.3 and …9.8
- CVE-2003-1234Integer overflow in the f_count counter in FreeBSD before 4.…
- CVE-2003-1235BRW WebWeaver 1.03 allows remote attackers to obtain sensiti…
Are you affected by CVE-2003-1229?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
