Search

published date: December 31, 2004

CVE-2004-2393 : Java Secure Socket Extension...

Description

Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS.

Product(s):

  • Sun JSSE 1.0.3
  • Sun JSSE 1.0.3 _01
  • Sun JSSE 1.0.3 _02

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-2393, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-2393 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?