CVE-2016-8212
Published: Feb 3, 2017
Modified: Aug 6, 2024
Description
An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validation Vulnerability. OCSP responses have two time values: thisUpdate and nextUpdate. These specify a validity period; however, both values are optional. Crypto-J treats the lack of a nextUpdate as indicating that the OCSP response is valid indefinitely instead of restricting its validity for a brief period surrounding the thisUpdate time. This vulnerability is similar to the issue described in CVE-2015-4748.
| Vendor | Product | Versions |
|---|---|---|
n/a | RSA BSAFE Crypto-J RSA BSAFE Crypto-J versions prior to 6.2.2 | affected RSA BSAFE Crypto-J RSA BSAFE Crypto-J versions prior to 6.2.2 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now