CVE-2011-4314
published 2012-01-27CVE-2011-4314: message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before…
PriorityP426medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
3.20%
86.7th percentile
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openid4java | < openid4java 0.9.6.662-1 (bookworm) | openid4java 0.9.6.662-1 (bookworm) |
| kay_framework_project | kay_framework | <= 1.0.1 | — |
| kay_framework_project | kay_framework | — | — |
| kay_framework_project | kay_framework | — | — |
| kay_framework_project | kay_framework | — | — |
| kay_framework_project | kay_framework | — | — |
| kay_framework_project | kay_framework | — | — |
| kay_framework_project | kay_framework | — | — |
| openid | openid4java | <= 0.9.5.593 | — |
| openid | openid4java | — | — |
| openid | openid4java | — | — |
| openid | openid4java | — | — |
| openid | openid4java | >= 0 < 0.9.6.662-1 | 0.9.6.662-1 |
| openid | openid4java | >= 0 < 0.9.6.662-1 | 0.9.6.662-1 |
| openid | openid4java | >= 0 < 0.9.6.662-1 | 0.9.6.662-1 |
| openid | openid4java | >= 0 < 0.9.6.662-1 | 0.9.6.662-1 |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenID4Java does not verify that Attribute Exchange (AX) information is signed
ghsa·2022-05-17
CVE-2011-4314 [MEDIUM] CWE-20 OpenID4Java does not verify that Attribute Exchange (AX) information is signed
OpenID4Java does not verify that Attribute Exchange (AX) information is signed
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
OSV
OpenID4Java does not verify that Attribute Exchange (AX) information is signed
osv·2022-05-17
CVE-2011-4314 [MEDIUM] OpenID4Java does not verify that Attribute Exchange (AX) information is signed
OpenID4Java does not verify that Attribute Exchange (AX) information is signed
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
OSV
CVE-2011-4314: message/ax/AxMessage
osv·2012-01-27·CVSS 5.8
CVE-2011-4314 [MEDIUM] CVE-2011-4314: message/ax/AxMessage
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
Red Hat
extension): MITM due to improper validation of AX attribute signatures
vendor_redhat·2011-05-05·CVSS 5.8
CVE-2011-4314 [MEDIUM] extension): MITM due to improper validation of AX attribute signatures
extension): MITM due to improper validation of AX attribute signatures
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
Package: Security (Red Hat JBoss BRMS 5) - Affected
Debian
CVE-2011-4314: openid4java - message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss En...
vendor_debian·2011·CVSS 5.8
CVE-2011-4314 [MEDIUM] CVE-2011-4314: openid4java - message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss En...
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
Scope: local
bookworm: resolved (fixed in 0.9.6.662-1)
bullseye: resolved (fixed in 0.9.6.662-1)
forky: resolved (fixed in 0.9.6.662-1)
sid: resolved (fixed in 0.9.6.662-1)
trixie: resolved (fixed in 0.9.6.662-1)
No detection rules found.
No public exploits indexed.
http://openid.net/2011/05/05/attribute-exchange-security-alert/http://rhn.redhat.com/errata/RHSA-2012-0441.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0519.htmlhttp://secunia.com/advisories/44496http://secunia.com/advisories/48697http://secunia.com/advisories/48954http://securitytracker.com/id?1026400http://www.openwall.com/lists/oss-security/2011/11/16/1http://www.openwall.com/lists/oss-security/2011/11/17/1http://www.redhat.com/support/errata/RHSA-2011-1804.htmlhttps://issues.jboss.org/browse/JBEPP-1368https://issues.jboss.org/browse/SOA-3597http://openid.net/2011/05/05/attribute-exchange-security-alert/http://rhn.redhat.com/errata/RHSA-2012-0441.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0519.htmlhttp://secunia.com/advisories/44496http://secunia.com/advisories/48697http://secunia.com/advisories/48954http://securitytracker.com/id?1026400http://www.openwall.com/lists/oss-security/2011/11/16/1http://www.openwall.com/lists/oss-security/2011/11/17/1http://www.redhat.com/support/errata/RHSA-2011-1804.htmlhttps://issues.jboss.org/browse/JBEPP-1368https://issues.jboss.org/browse/SOA-3597
2012-01-27
Published