CVE Database
/

CVE-2016-8212

Back to search

CVE-2016-8212

Published: Feb 3, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validation Vulnerability. OCSP responses have two time values: thisUpdate and nextUpdate. These specify a validity period; however, both values are optional. Crypto-J treats the lack of a nextUpdate as indicating that the OCSP response is valid indefinitely instead of restricting its validity for a brief period surrounding the thisUpdate time. This vulnerability is similar to the issue described in CVE-2015-4748.

VendorProductVersions

n/a

RSA BSAFE Crypto-J RSA BSAFE Crypto-J versions prior to 6.2.2

affected
RSA BSAFE Crypto-J RSA BSAFE Crypto-J versions prior to 6.2.2

References

95831
vdb-entry
x_refsource_BID
1037732
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now