Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19749
HistoryMay 16, 2019 - 3:23 a.m.

Authentication Bypass

2019-05-1603:23:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.004 Low

EPSS

Percentile

73.4%

Tomcat is vulnerable to authentication bypass vulnerability. This is because, when using an OCSP responder Apache Tomcat Native does not correctly handle invalid responses. Users could authenticate with revoked certificates when using mutual TLS as the revoked client certificates are improperly validated.

References