Rapid7 Vulnerability & Exploit Database

HP-UX: CVE-2003-1229: Potential Sec. Vulnerability in Java VM, JSSE, Plug-in, and Webstart. (rev.1)

Back to Search

HP-UX: CVE-2003-1229: Potential Sec. Vulnerability in Java VM, JSSE, Plug-in, and Webstart. (rev.1)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
12/31/2003
Created
07/25/2018
Added
08/11/2017
Modified
09/12/2017

Description

X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.

Solution(s)

  • hpux-apply-phss-28685
  • hpux-apply-phss-28686

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;