#VU91 Client certificate authentication bypass in Apache HTTP Server and Oracle Enterprise Manager Ops Center - CVE-2016-4979
Published: July 6, 2016 / Updated: January 4, 2017
Apache HTTP Server
Oracle Enterprise Manager Ops Center
Apache Foundation
Oracle
Description
The vulnerability allows a remote attacker to bypass client certificate authentication.
The vulnerability exists due to HTTP/2 certificate validation error. A remote unauthenticated attacker can bypass client certificate authentication and access web resources on the target system.
Systems using the mod_http2 module with activated h2 and h2c protocols in configuration are affected.
Successful exploitation of this vulnerability may result unauthorized access to resources on the web server.