Sun Security Certificate Compromise

MEDIUM (5.1) Patch Available Patch Patch

Threat Intelligence

Low Risk
EPSS Score: 0.27% chance of exploitation (percentile: 50%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun. This vulnerability affects any system using these compromised certificates.

Am I affected?

This is a general advisory for systems using Sun security certificates. If you use Sun security certificates in your Java applications, you're likely affected. Version info not stated in the advisory. Check with: find / -name "sunsec*.jar" 2>/dev/null

Affected Products

Sun Microsystems / Security Certificates

How to fix

Download and install the patched certificate from: http://www.cert.org/advisories/CA-2000-19.html
- Update your Java application to use the patched certificate.