SSL/TLS Certificate Validation Flaw in Java Secure Socket Extension by Sun Microsystems
CVE-2004-2393

Currently unrated

Key Information:

Vendor

Oracle

Status
Vendor
CVE Published:
31 December 2004

What is CVE-2004-2393?

The Java Secure Socket Extension (JSSE) versions 1.0.3 and 1.0.3_2 are susceptible to a flaw where they fail to adequately validate the certificate chain of clients or servers. This weakness enables remote attackers to potentially execute man-in-the-middle attacks, allowing them to impersonate legitimate peers during SSL/TLS communications. The flaw underscores the importance of proper certificate management and validation to ensure secure data exchange.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.