Back to search
CVE-2011-4314
Published: Jan 27, 2012
Modified: Aug 7, 2024
PUBLISHED
Description
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2011:1804
vendor-advisory
x_refsource_REDHAT
44496
third-party-advisory
x_refsource_SECUNIA
http://openid.net/2011/05/05/attribute-exchange-security-alert/
x_refsource_CONFIRM
RHSA-2012:0519
vendor-advisory
x_refsource_REDHAT
48954
third-party-advisory
x_refsource_SECUNIA
RHSA-2012:0441
vendor-advisory
x_refsource_REDHAT
https://issues.jboss.org/browse/SOA-3597
x_refsource_CONFIRM
https://issues.jboss.org/browse/JBEPP-1368
x_refsource_CONFIRM
1026400
vdb-entry
x_refsource_SECTRACK
48697
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now