Apache Tomcat Native Connector Vulnerability in Parsing Client Certificates
CVE-2017-15698
5.9MEDIUM
What is CVE-2017-15698?
The Apache Tomcat Native Connector 1.2.0 through 1.2.14 and 1.1.23 to 1.1.34 has a vulnerability that arises when processing the AIA-Extension field of client certificates. Specifically, the handling of fields exceeding 127 bytes is flawed, leading to situations where the OCSP (Online Certificate Status Protocol) checks are bypassed. Consequently, client certificates that should be invalidated based on proper OCSP validation could potentially be accepted. This issue only affects users who have enabled OCSP checks; those not utilizing this feature are not impacted.
Affected Version(s)
Apache Tomcat Native 1.2.0 to 1.2.14
Apache Tomcat Native 1.1.23 to 1.1.34