Apache Tomcat Native Connector Vulnerability in Parsing Client Certificates
CVE-2017-15698

5.9MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
31 January 2018

Summary

The Apache Tomcat Native Connector 1.2.0 through 1.2.14 and 1.1.23 to 1.1.34 has a vulnerability that arises when processing the AIA-Extension field of client certificates. Specifically, the handling of fields exceeding 127 bytes is flawed, leading to situations where the OCSP (Online Certificate Status Protocol) checks are bypassed. Consequently, client certificates that should be invalidated based on proper OCSP validation could potentially be accepted. This issue only affects users who have enabled OCSP checks; those not utilizing this feature are not impacted.

Affected Version(s)

Apache Tomcat Native 1.2.0 to 1.2.14

Apache Tomcat Native 1.1.23 to 1.1.34

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.