Medium severity5.9NVD Advisory· Published Jan 31, 2018· Updated Jun 17, 2026
CVE-2017-15698
CVE-2017-15698
Description
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 1.2.0 to 1.2.14, 1.1.23 to 1.1.34
- osv-coords2 versionspkg:rpm/suse/libtcnative-1-0&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/libtcnative-1-0&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS
< 1.3.4-12.5.5.2+ 1 more
- (no CPE)range: < 1.3.4-12.5.5.2
- (no CPE)range: < 1.3.4-12.5.5.2
- Range: 1.2.0 to 1.2.14
Patches
Vulnerability mechanics
References
10- www.securitytracker.com/id/1040390nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:0465nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2018:0466nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/02/msg00011.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2018/dsa-4118nvdThird Party Advisory
- lists.apache.org/thread.html/6eb0a53e5827d97db1a05c736d01101fec21202a5b8fc77bb0eaaed8%40%3Cannounce.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3Envd
News mentions
0No linked articles in our index yet.