VDB

CVE-2018-8019

CVE-2018-8019 PUBLISHED CVSS 7.400000095367432 HIGH

When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate with revoked certificates when using mutual TLS. Users not using OCSP checks are not affected by this vulnerability.

EPSS 4.07% · 90.3th percentile

Risk Scores

CVSS 3.0
7.400000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
4.07%
90.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTStomcat-native1.1.33-1, 0

Timeline

  • Jul 31, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 2, 2022 EPSS Score
  • May 4, 2022 EPSS Score
  • Jul 6, 2022 EPSS Score
  • Nov 9, 2022 EPSS Score
  • Jan 11, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›