cbcvebase.
CVE-2017-15698
published 2018-01-31

CVE-2017-15698: When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle…

PriorityP431medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
3.53%
87.9th percentile
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachetomcat_native1.1.23 – 1.1.34
apachetomcat_native1.2.0 – 1.2.14
apache_software_foundationapache_tomcat_native
apache_software_foundationapache_tomcat_native
debiandebian_linux
debiandebian_linux
debiantomcat-native< tomcat-native 1.2.16-1 (bookworm)tomcat-native 1.2.16-1 (bookworm)

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.