SSL/TLS Certificate Validation Flaw in Java Secure Socket Extension by Sun Microsystems
CVE-2004-2393
Currently unrated
What is CVE-2004-2393?
The Java Secure Socket Extension (JSSE) versions 1.0.3 and 1.0.3_2 are susceptible to a flaw where they fail to adequately validate the certificate chain of clients or servers. This weakness enables remote attackers to potentially execute man-in-the-middle attacks, allowing them to impersonate legitimate peers during SSL/TLS communications. The flaw underscores the importance of proper certificate management and validation to ensure secure data exchange.
References
Timeline
Vulnerability Reserved
Vulnerability published