<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:16:11.508936+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-116789</id>
    <title>EUVD-2026-116789</title>
    <updated>2026-10-02T23:16:11.524470+00:00</updated>
    <content>EUVD-2026-116789</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-116789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2011-4314</id>
    <title>fkie_cve-2011-4314</title>
    <updated>2026-10-02T23:16:11.524511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2011-4314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j473-c3rr-rx9p</id>
    <title>GHSA-j473-c3rr-rx9p — OpenID4Java does not verify that Attribute Exchange (AX) information is signed</title>
    <updated>2026-10-02T23:16:11.524544+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.openid4java:openid4java</p>
<p>message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j473-c3rr-rx9p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2011-4314</id>
    <title>gsd-2011-4314</title>
    <updated>2026-10-02T23:16:11.524570+00:00</updated>
    <content>gsd-2011-4314</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2011-4314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2011:1798</id>
    <title>RHSA-2011:1798 — Red Hat Security Advisory: JBoss Enterprise Application Platform 5.1.2 update</title>
    <updated>2026-10-02T23:16:11.524583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Invoker servlets authentication bypass (HTTP verb tampering) extension): MITM due to improper validation of AX attribute signatures</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2011:1798"/>
  </entry>
</feed>
