SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-15698

Users not using OCSP checks are not affected by this vulnerability.

MEDIUM 5.9EPSS 3.53%

Does this matter?

Lower severity and a low EPSS score (3.53%). Track it; it rarely justifies an emergency change on its own.

Description

When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
3.53% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
apache/tomcat native · debian/debian linux
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.