Lucene search

K
cve[email protected]CVE-2011-4314
HistoryJan 27, 2012 - 3:55 p.m.

CVE-2011-4314

2012-01-2715:55:04
CWE-20
web.nvd.nist.gov
32
openid4java
jboss
step2
kay framework
vulnerability
mitm
cve-2011-4314
nvd

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.3%

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

Affected configurations

NVD
Node
kay_framework_projectkay_frameworkRange1.0.1
OR
kay_framework_projectkay_frameworkMatch0.0.0-
OR
kay_framework_projectkay_frameworkMatch0.1.0
OR
kay_framework_projectkay_frameworkMatch0.2.0
OR
kay_framework_projectkay_frameworkMatch0.3.0
OR
kay_framework_projectkay_frameworkMatch0.8.0
OR
kay_framework_projectkay_frameworkMatch1.0.0
OR
openidopenid4javaRange0.9.5.593
OR
openidopenid4javaMatch0.9.2
OR
openidopenid4javaMatch0.9.3
OR
openidopenid4javaMatch0.9.4.339
OR
redhatjboss_enterprise_application_platformMatch5.1.0
OR
redhatjboss_enterprise_application_platformMatch5.1.1
OR
redhatjboss_enterprise_application_platformMatch5.1.2

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.3%