« Volver al listado

CVE-2011-4314

Estado: ModificadaMedia (5.8)—

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4314",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-01-27T15:55:04.500",
  "references": [
    {
      "url": "http://openid.net/2011/05/05/attribute-exchange-security-alert/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-0441.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-0519.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/44496",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/48697",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/48954",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://securitytracker.com/id?1026400",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/11/16/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/11/17/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2011-1804.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://issues.jboss.org/browse/JBEPP-1368",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://issues.jboss.org/browse/SOA-3597",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://openid.net/2011/05/05/attribute-exchange-security-alert/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-0441.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-0519.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/44496",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/48697",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/48954",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1026400",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/11/16/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/11/17/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2011-1804.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.jboss.org/browse/JBEPP-1368",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.jboss.org/browse/SOA-3597",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack."
    },
    {
      "lang": "es",
      "value": "message/ax/AxMessage.java en OpenID4Java antes v0.9.6 final, tal y como se utiliza en JBoss Enterprise Application Platform v5.1 antes de v5.1.2, Step2, Kay Framework antes de la versión v1.0.2, y posiblemente otros productos no verifica que la información de intercambio de atributos (Attribute Exchange - AX) ha sido firmada, lo que permite a atacantes remotos modificar la información AX potencialmente sensible sin ser detectado a través de un ataque \"Man-in-the-middle\" (MITM)."
    }
  ],
  "lastModified": "2026-06-16T23:34:45.363",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kay_framework_project:kay_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C34585EE-6B3D-4BAA-A48B-355751340745",
              "versionEndIncluding": "1.0.1"
            },
            {
              "criteria": "cpe:2.3:a:kay_framework_project:kay_framework:0.0.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "497F44FA-8826-4F7D-97E3-D2AA02734A05"
            },
            {
              "criteria": "cpe:2.3:a:kay_framework_project:kay_framework:0.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0CB7EFD-538C-4573-9C5E-51CE3EFE4942"
            },
            {
              "criteria": "cpe:2.3:a:kay_framework_project:kay_framework:0.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFD65FAE-117F-4836-8F18-0993FC7273E8"
            },
            {
              "criteria": "cpe:2.3:a:kay_framework_project:kay_framework:0.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "395C136F-0B5D-46E1-BF57-2D71677282BB"
            },
            {
              "criteria": "cpe:2.3:a:kay_framework_project:kay_framework:0.8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AE498E3-51AB-4E12-BD4C-D1FF6729E238"
            },
            {
              "criteria": "cpe:2.3:a:kay_framework_project:kay_framework:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC6154A9-F506-47B3-94B8-ACA20BCB4C86"
            },
            {
              "criteria": "cpe:2.3:a:openid:openid4java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9618CEF-6F14-469A-A27E-5FEDDC0B939A",
              "versionEndIncluding": "0.9.5.593"
            },
            {
              "criteria": "cpe:2.3:a:openid:openid4java:0.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "434CDA90-8E27-45AC-8235-91E1FAACA016"
            },
            {
              "criteria": "cpe:2.3:a:openid:openid4java:0.9.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0D0288B-293C-4DAF-A2F0-A8CDA9B5FD3A"
            },
            {
              "criteria": "cpe:2.3:a:openid:openid4java:0.9.4.339:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9EC5D95-9C93-4B71-8C90-1451FB863DA7"
            },
            {
              "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "972C5C87-E982-44A5-866D-FDEACB5203B8"
            },
            {
              "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C13890AE-5FDE-4698-8A2E-1B2FA0A313AF"
            },
            {
              "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A785F07-9B76-4153-B676-29C9682B2F73"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}