Oval Definition:oval:org.opensuse.security:def:20188019
Revision Date:2022-09-02Version:1
Title:CVE-2018-8019
Description:

When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate with revoked certificates when using mutual TLS. Users not using OCSP checks are not affected by this vulnerability.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-8019
SUSE-SU-2019:14014-1
Mitre CVE-2018-8019
SUSE CVE-2018-8019
SUSE-SU-2019:14014-1
Platform(s):SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise Point of Sale 11 SP3
SUSE Linux Enterprise Server 11 SP1-TERADATA
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server 11 SP4-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 11 SP1-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP3-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Software Development Kit 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP5
SUSE OpenStack Cloud 7
Product(s):
Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND libtcnative-1-0 is affected
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1.12 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
  • AND libtcnative-1-0-devel-1.2.17-1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Point of Sale 11 SP3 is installed
  • OR SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Point of Sale 11 SP3 is installed
  • OR SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP3-TERADATA is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP3-TERADATA is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
  • AND libtcnative-1-0-devel-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
  • AND libtcnative-1-0-devel-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3 is installed
  • OR Package Information
  • SUSE Linux Enterprise Software Development Kit 12 SP5 is installed
  • AND libtcnative-1-0-devel-1.2.23-3.3 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Point of Sale 11 SP3 is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND libtcnative-1-0 is affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3.3 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND libtcnative-1-0 is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3.3 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • OR SUSE Linux Enterprise Software Development Kit 12 SP5 is installed
  • AND libtcnative-1-0-devel-1.2.23-3.3.3 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1.12 is installed
  • OR Package Information
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • OR SUSE Linux Enterprise Server 12 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • OR SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
  • AND libtcnative-1-0-devel-1.2.17-1.12 is installed
  • BACK