message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2012-01-27T15:00:00

Updated: 2012-11-27T10:00:00

Reserved: 2011-11-04T00:00:00


Link: CVE-2011-4314

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2012-01-27T15:55:04.500

Modified: 2013-02-15T04:50:40.607


Link: CVE-2011-4314

JSON object: View

cve-icon Redhat Information

No data.

CWE