CVE-2015-1793: OpenSSL

Medium severity, CVSS 6.5. EPSS: 58.4% chance of exploitation in the next 30 days.

The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.

Affected products

  • OpenSSL OpenSSL: version 1.0.1n only; version 1.0.1o only; version 1.0.2b only; version 1.0.2c only
  • Oracle Jd Edwards Enterpriseone Tools: version 9.1 only; version 9.2 only
  • Oracle Opus 10g Ethernet Switch Family: up to and including 2.0.0.6
  • Oracle Supply Chain Products Suite: version 6.1.2.2 only; version 6.1.3.0 only; version 6.2.0 only

Published 2015-07-09. Last modified 2026-06-17.