CVE-2011-4314: Input Validation
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4314?
CVE-2011-4314 has been classified as a medium severity vulnerability.
How do I fix CVE-2011-4314?
To mitigate CVE-2011-4314, upgrade OpenID4Java to version 0.9.6 or later and ensure that your other affected software components are also updated.
What software versions are affected by CVE-2011-4314?
CVE-2011-4314 affects OpenID4Java versions before 0.9.6, Kay Framework versions up to 1.0.1, and JBoss Enterprise Application Platform versions before 5.1.2.
What type of attack can be executed due to CVE-2011-4314?
CVE-2011-4314 allows remote attackers to modify the Attribute Exchange (AX) information due to lack of signature verification.
Is CVE-2011-4314 still relevant today?
While CVE-2011-4314 is an older vulnerability, it remains relevant for systems using the affected versions of the software mentioned.