Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-4314

Опубликовано: 27 янв. 2012
Источник: debian
EPSS Низкий

Описание

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openid4javafixed0.9.6.662-1package
jbossas4not-affectedpackage

EPSS

Процентиль: 87%
0.03201
Низкий

Связанные уязвимости

redhat
больше 15 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

nvd
больше 14 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

github
около 4 лет назад

OpenID4Java does not verify that Attribute Exchange (AX) information is signed

EPSS

Процентиль: 87%
0.03201
Низкий