Impact
Apache Tomcat’s OpenSSL and OpenSSL-FFM TLS implementations fail to check Certificate Revocation Lists when a certificate is stored in a keystore, allowing an attacker to use a revoked certificate without detection. This weakness can enable a man‑in‑the‑middle or unauthorized session establishment, compromising confidentiality and integrity of secure connections.
Affected Systems
The vulnerability affects Apache Tomcat versions 8.5.0 through 8.5.100, 9.0.0-M1 through 9.0.121, 10.1.0-M1 through 10.1.58, and 11.0.0-M1 through 11.0.25, including all EOL releases listed. Unsupported versions beyond those ranges may also be affected.
Risk and Exploitability
The CVSS metric is not provided, but the failure to enforce revocation checks is a high‑impact flaw that can be abused by attackers who control or can present a revoked certificate. With no EPSS score available and the vulnerability not listed in CISA KEV, the exact exploitation probability is unknown, yet the potential impact warrants prompt remediation. The likely exploitation path involves network‑connected servers running the affected Tomcat releases with TLS enabled and certificates sourced from a keystore, making the attack vector remote over the internet or internal network.
OpenCVE Enrichment