OpenID OpenID4Java 0.9.3

CPE Details

OpenID OpenID4Java 0.9.3
0.9.3
2012-01-30
14h18 +00:00
2012-02-16
19h14 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:openid:openid4java:0.9.3:*:*:*:*:*:*:*

Informations

Vendor

openid

Product

openid4java

Version

0.9.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2011-4314 2012-01-27 14h00 +00:00 message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
5.8