Логотип exploitDog
bind:CVE-2011-4314
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2011-4314

Количество 4

Количество 4

redhat логотип

CVE-2011-4314

почти 15 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4314

около 14 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2011-4314

около 14 лет назад

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used i ...

CVSS2: 5.8
EPSS: Низкий
github логотип

GHSA-j473-c3rr-rx9p

больше 3 лет назад

OpenID4Java does not verify that Attribute Exchange (AX) information is signed

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2011-4314

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-4314

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 5.8
1%
Низкий
около 14 лет назад
debian логотип
CVE-2011-4314

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used i ...

CVSS2: 5.8
1%
Низкий
около 14 лет назад
github логотип
GHSA-j473-c3rr-rx9p

OpenID4Java does not verify that Attribute Exchange (AX) information is signed

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу