CVE-2017-15698
published 2018-01-31CVE-2017-15698: When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle…
PriorityP431medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
3.53%
87.9th percentile
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat_native | 1.1.23 – 1.1.34 | — |
| apache | tomcat_native | 1.2.0 – 1.2.14 | — |
| apache_software_foundation | apache_tomcat_native | — | — |
| apache_software_foundation | apache_tomcat_native | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat-native | < tomcat-native 1.2.16-1 (bookworm) | tomcat-native 1.2.16-1 (bookworm) |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat-native: Mishandling of client certificates can allow for OCSP check bypass
vendor_redhat·2018-01-31·CVSS 5.9
CVE-2017-15698 [MEDIUM] CWE-299 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass
tomcat-native: Mishandling of client certificates can allow for OCSP check bypass
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.
Package: tomcat-native (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: tomcat-native (Red Hat JBoss Enterprise Application Platform 6) - Will not fix
Package: tomcat-native (Red Hat JBoss Enterprise Web Server 2) - Will not fix
Debian
CVE-2017-15698: tomcat-native - When parsing the AIA-Extension field of a client certificate, Apache Tomcat Nati...
vendor_debian·2017·CVSS 5.9
CVE-2017-15698 [MEDIUM] CVE-2017-15698: tomcat-native - When parsing the AIA-Extension field of a client certificate, Apache Tomcat Nati...
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.
Scope: local
bookworm: resolved (fixed in 1.2.16-1)
bullseye: resolved (fixed in 1.2.16-1)
forky: resolved (fixed in 1.2.16-1)
sid: resolved (fixed in 1.2.16-1)
trixie: resolved (fixed in 1.2.16-1)
GHSA
GHSA-ppg5-72hh-9jj4: When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1
ghsa_unreviewed·2022-05-14
CVE-2017-15698 [MEDIUM] CWE-295 GHSA-ppg5-72hh-9jj4: When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.
OSV
CVE-2017-15698: When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1
osv·2018-01-31·CVSS 5.9
CVE-2017-15698 [MEDIUM] CVE-2017-15698: When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass [fedora-all]
bugzilla·2018-02-01·CVSS 5.9
CVE-2017-15698 [MEDIUM] CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass [fedora-all]
CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass
bugzilla·2018-02-01·CVSS 5.9
CVE-2017-15698 [MEDIUM] CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass
CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.
Versions Affected:
Apache Tomcat Native 1.2.0 to 1.2.14
Apache Tomcat Native 1.1.23 to 1.1.34
Upstream Advisory:
http://tomcat.10.x6.nabble.com/SECURITY-CVE-2017-15698-Apache-Tomcat-Native-Connector-OCSP-check-omitted-td5071564.html
Upstream Patches:
http://svn.apache.org/viewvc?view=revision&revision
Bugzilla
CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass [epel-all]
bugzilla·2018-02-01·CVSS 5.9
CVE-2017-15698 [MEDIUM] CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass [epel-all]
CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
http://www.securitytracker.com/id/1040390https://access.redhat.com/errata/RHSA-2018:0465https://access.redhat.com/errata/RHSA-2018:0466https://lists.apache.org/thread.html/6eb0a53e5827d97db1a05c736d01101fec21202a5b8fc77bb0eaaed8%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/02/msg00011.htmlhttps://www.debian.org/security/2018/dsa-4118http://www.securitytracker.com/id/1040390https://access.redhat.com/errata/RHSA-2018:0465https://access.redhat.com/errata/RHSA-2018:0466https://lists.apache.org/thread.html/6eb0a53e5827d97db1a05c736d01101fec21202a5b8fc77bb0eaaed8%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/02/msg00011.htmlhttps://www.debian.org/security/2018/dsa-4118
2018-01-31
Published