Oval Definition:oval:org.opensuse.security:def:20188020
Revision Date:2022-09-02Version:1
Title:CVE-2018-8020
Description:

Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-8020
SUSE-SU-2019:14014-1
Mitre CVE-2018-8020
SUSE CVE-2018-8020
SUSE-SU-2019:14014-1
Platform(s):SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise Point of Sale 11 SP3
SUSE Linux Enterprise Server 11 SP1-TERADATA
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server 11 SP4-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 11 SP1-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP3-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Software Development Kit 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP5
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND libtcnative-1-0 is affected
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1.12 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
  • AND libtcnative-1-0-devel-1.2.17-1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Point of Sale 11 SP3 is installed
  • OR SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Point of Sale 11 SP3 is installed
  • OR SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP3-TERADATA is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP3-TERADATA is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
  • AND libtcnative-1-0-devel-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
  • AND libtcnative-1-0-devel-1.2.17-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3 is installed
  • OR Package Information
  • SUSE Linux Enterprise Software Development Kit 12 SP5 is installed
  • AND libtcnative-1-0-devel-1.2.23-3.3 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Point of Sale 11 SP3 is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • OR SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • AND libtcnative-1-0-1.3.4-12.5.5.2 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP3 is installed
  • AND libtcnative-1-0 is affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3.3 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1.12 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • OR SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND libtcnative-1-0 is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libtcnative-1-0-1.2.23-3.3.3 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • OR SUSE Linux Enterprise Software Development Kit 12 SP5 is installed
  • AND libtcnative-1-0-devel-1.2.23-3.3.3 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libtcnative-1-0-1.2.17-1.12 is installed
  • OR Package Information
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • OR SUSE Linux Enterprise Server 12 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • OR SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
  • AND libtcnative-1-0-devel-1.2.17-1.12 is installed
  • BACK