sun jre CVE-2003-1229 in Sun and Oracle Products
Published on December 31, 2003

product logo product logo
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.

Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2003-1229

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2003-1229 are published in these products:

 
 
 
 
 

Exploit Probability

EPSS
1.29%
Percentile
79.49%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.