cbcvebase.

Debian Tomcat-Native vulnerabilities

4 known vulnerabilities affecting debian/tomcat-native.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2009-3555P1MEDIUMCVSS 5.8ExploitedPoCfixed in apache2 2.2.14-2 (bookworm)2009
CVE-2009-3555 [MEDIUM] CVE-2009-3555: apache2 - The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Micr... The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate reneg
debian
CVE-2018-8020P3HIGHCVSS 7.4fixed in tomcat-native 1.2.17-1 (bookworm)2018
CVE-2018-8020 [HIGH] CVE-2018-8020: tomcat-native - Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does n... Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Us
debian
CVE-2018-8019P3HIGHCVSS 7.4fixed in tomcat-native 1.2.17-1 (bookworm)2018
CVE-2018-8019 [HIGH] CVE-2018-8019: tomcat-native - When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to ... When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate with revoked certificates when using mutual TLS. Users not using OCSP checks are not affected by this vuln
debian
CVE-2017-15698P4MEDIUMCVSS 5.9fixed in tomcat-native 1.2.16-1 (bookworm)2017
CVE-2017-15698 [MEDIUM] CVE-2017-15698: tomcat-native - When parsing the AIA-Extension field of a client certificate, Apache Tomcat Nati... When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made)
debian