CVE-2003-1229
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.63% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- oracle/jre · sun/java web start · sun/jsse
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0334.htmlBroken Link
- http://java.sun.com/products/jsse/CHANGES.txtBroken Link, Vendor Advisory
- http://secunia.com/advisories/7943Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1006007Broken Link, Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1007483Broken Link, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-50081-1Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/6682Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1006001Broken Link, Third Party Advisory, VDB Entry
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0301-239Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11182Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5883Broken Link
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0334.htmlBroken Link
- http://java.sun.com/products/jsse/CHANGES.txtBroken Link, Vendor Advisory
- http://secunia.com/advisories/7943Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1006007Broken Link, Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1007483Broken Link, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-50081-1Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/6682Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1006001Broken Link, Third Party Advisory, VDB Entry
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0301-239Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11182Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5883Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.