CVE-2003-1229
Last modified
CVE-2003-1229 is a vulnerability of currently unknown severity. X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.. EPSS estimates a 4.63% chance of exploitation in the next 30 days.
Description
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Jre | >= 1.3.0, <= 1.4.1 |
| Sun | Java Web Start | >= 1.0, <= 1.2 |
| Sun | Jsse | 1.0.3 |
References
- http://java.sun.com/products/jsse/CHANGES.txtBroken Link, Vendor Advisory
- http://secunia.com/advisories/7943Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1006007Broken Link, Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1007483Broken Link, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-50081-1Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/6682Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1006001Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11182Third Party Advisory, VDB Entry
- http://java.sun.com/products/jsse/CHANGES.txtBroken Link, Vendor Advisory
- http://secunia.com/advisories/7943Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1006007Broken Link, Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1007483Broken Link, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-50081-1Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/6682Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1006001Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11182Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1229?
How severe is CVE-2003-1229?
How do I fix CVE-2003-1229?
Are you affected by CVE-2003-1229?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
