Apache Tomcat Native Connector Vulnerability in Parsing Client Certificates
CVE-2017-15698
5.9MEDIUM
Summary
The Apache Tomcat Native Connector 1.2.0 through 1.2.14 and 1.1.23 to 1.1.34 has a vulnerability that arises when processing the AIA-Extension field of client certificates. Specifically, the handling of fields exceeding 127 bytes is flawed, leading to situations where the OCSP (Online Certificate Status Protocol) checks are bypassed. Consequently, client certificates that should be invalidated based on proper OCSP validation could potentially be accepted. This issue only affects users who have enabled OCSP checks; those not utilizing this feature are not impacted.
Affected Version(s)
Apache Tomcat Native 1.2.0 to 1.2.14
Apache Tomcat Native 1.1.23 to 1.1.34
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved