CVE-2003-1516: Medium severity Sun Java Plug-In vulnerability
The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.201 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Until a vendor-supplied fix is available, block or disable the Sun Java Embedding Plugin version 1.4.2_01 from running — e.g., disable the plugin in browsers, prevent execution of the plugin binary, or isolate hosts running that exact version.
- Operational
Inventory your environment for instances of the Sun Java Embedding Plugin and identify any installations reporting version 1.4.2_01 (the org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 is vulnerable).
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1516?
CVE-2003-1516 has been classified as a high-severity vulnerability due to its potential to allow unauthorized access to applet data.
How do I fix CVE-2003-1516?
To fix CVE-2003-1516, you should upgrade to a later version of the Java Plug-in that corrects this vulnerability.
What products are affected by CVE-2003-1516?
CVE-2003-1516 specifically affects Sun Java Plug-in 1.4.2_01.
What type of attack can CVE-2003-1516 facilitate?
CVE-2003-1516 can facilitate attacks that allow untrusted applets to read or write data belonging to trusted applets.
Is there a workaround for CVE-2003-1516?
Currently, the most effective workaround for CVE-2003-1516 is to avoid the use of the affected version of the Java Plug-in.