Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19750
HistoryMay 16, 2019 - 3:23 a.m.

Authentication Bypass

2019-05-1603:23:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.012 Low

EPSS

Percentile

85.3%

Tomcat is vulnerable to authentication bypass vulnerability. This is because, when using pre-produced responses from an OCSP responder, Tomcat Native does not correctly validate the status of certificates. Users with revoked certificates could authenticate when using mutual TLS as the revoked client certificates are not properly identified.

References