Vulnerabilities > CVE-2004-2393 - Unspecified vulnerability in SUN Jsse 1.0.3/1.0.301/1.0.302

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
sun

Summary

Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS.

Vulnerable Configurations

Part Description Count
Application
Sun
3