Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2011-4314

больше 15 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4314

больше 14 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2011-4314

больше 14 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used i ...

CVSS2: 5.8
EPSS: Низкий
github логотип

GHSA-j473-c3rr-rx9p

около 4 лет назад

OpenID4Java does not verify that Attribute Exchange (AX) information is signed

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2011-4314

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 4.3
3%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-4314

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 5.8
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-4314

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used i ...

CVSS2: 5.8
3%
Низкий
больше 14 лет назад
github логотип
GHSA-j473-c3rr-rx9p

OpenID4Java does not verify that Attribute Exchange (AX) information is signed

3%
Низкий
около 4 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.