CVE-2017-15698

UnknownEPSS 3.59%

Last modified

CVE-2017-15698 is a vulnerability of currently unknown severity. When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. EPSS estimates a 3.59% chance of exploitation in the next 30 days.

Description

When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.

Metrics

EPSS Probability
3.59%

88.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheTomcat Native>= 1.1.23, <= 1.1.34
ApacheTomcat Native>= 1.2.0, <= 1.2.14
DebianDebian Linux8.0
DebianDebian Linux9.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-15698?
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.
How severe is CVE-2017-15698?
Severity scoring for CVE-2017-15698 is pending analysis. The EPSS model estimates a 3.59% probability of exploitation in the next 30 days.
How do I fix CVE-2017-15698?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-15698?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST