CVE-2003-1229
Summary
| CVE | CVE-2003-1229 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| (HP Issues Fix for Virtualvault) Sun Java Secure Socket Extension (JSSE) May Incorrectly Authenticate Invalid Entities - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Oracle Java Technologies | Oracle | af854a3a-2127-422b-91ae-364da2661108 | java.sun.com | Broken Link, Vendor Advisory |
| Neohapsis Archives - Bugtraq - Incorrect Certificate Validation in Java Secure Socket Extension - From a.loots_at_itsec-ss.nl | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Broken Link |
| Secunia - Advisories - Java fails to validate certificates | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Patch, Vendor Advisory |
| #50081: Incorrect Certificate Validation in Java Secure Socket Extension (JSSE), Java Plug-In and Java Web Start java.lang.NullPointerException | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link, Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| (HP Issues Fix) Sun Java Secure Socket Extension (JSSE) May Incorrectly Authenticate Invalid Entities - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Sun Java Secure Socket Extension (JSSE) May Incorrectly Authenticate Invalid Entities - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Sun JSSE/Java Plug-In/Java Web Start Incorrect Certificate Validation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Patch, Third Party Advisory, VDB Entry |
| www1.itrc.hp.com/service/cki/docDisplay.do | af854a3a-2127-422b-91ae-364da2661108 | www1.itrc.hp.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.