CVE-2017-15698 describes a parsing error in Apache Tomcat Native Connector versions 1.2.0-1.2.14 and 1.1.23-1.1.34 when handling client certificate AIA-Extension fields longer than 127 bytes, leading to skipped OCSP checks. This medium-severity vulnerability (CVSS 5.9) could allow invalid client certificates to be accepted, impacting systems that rely on OCSP for certificate validation. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.23, <= 1.1.34CPE matchmatch criteria | cpe:2.3:a:apache:tomcat_native:*:*:*:*:*:*:*:* | ||
>= 1.2.0, <= 1.2.14CPE matchmatch criteria | cpe:2.3:a:apache:tomcat_native:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.