Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4314

Опубликовано: 05 мая 2011
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5SecurityAffected
JBEWP 5 for RHEL 5apache-cxfFixedRHSA-2011:180308.12.2011
JBEWP 5 for RHEL 5cglibFixedRHSA-2011:180308.12.2011
JBEWP 5 for RHEL 5faceletsFixedRHSA-2011:180308.12.2011
JBEWP 5 for RHEL 5glassfish-jaxbFixedRHSA-2011:180308.12.2011
JBEWP 5 for RHEL 5glassfish-jsfFixedRHSA-2011:180308.12.2011
JBEWP 5 for RHEL 5jacorb-jbossFixedRHSA-2011:180308.12.2011
JBEWP 5 for RHEL 5jakarta-commons-logging-jbossFixedRHSA-2011:180308.12.2011
JBEWP 5 for RHEL 5jboss-aop2FixedRHSA-2011:180308.12.2011
JBEWP 5 for RHEL 5jbossas-webFixedRHSA-2011:180308.12.2011

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=754386extension): MITM due to improper validation of AX attribute signatures

EPSS

Процентиль: 78%
0.01136
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
около 14 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

debian
около 14 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used i ...

github
больше 3 лет назад

OpenID4Java does not verify that Attribute Exchange (AX) information is signed

EPSS

Процентиль: 78%
0.01136
Низкий

4.3 Medium

CVSS2