<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:16:09 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-116789</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-116789</link>
      <description>EUVD-2026-116789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-116789</guid>
    </item>
    <item>
      <title>fkie_cve-2011-4314</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2011-4314</link>
      <description>&lt;p&gt;message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2011-4314</guid>
    </item>
    <item>
      <title>GHSA-j473-c3rr-rx9p — OpenID4Java does not verify that Attribute Exchange (AX) information is signed</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j473-c3rr-rx9p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.openid4java:openid4java&lt;/p&gt;
&lt;p&gt;message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.openid4java:openid4java&lt;/p&gt;
&lt;p&gt;message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j473-c3rr-rx9p</guid>
    </item>
    <item>
      <title>gsd-2011-4314</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2011-4314</link>
      <description>gsd-2011-4314</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2011-4314</guid>
    </item>
    <item>
      <title>RHSA-2011:1798 — Red Hat Security Advisory: JBoss Enterprise Application Platform 5.1.2 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2011:1798</link>
      <description>&lt;p&gt;Invoker servlets authentication bypass (HTTP verb tampering) extension): MITM due to improper validation of AX attribute signatures&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Invoker servlets authentication bypass (HTTP verb tampering) extension): MITM due to improper validation of AX attribute signatures&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2011:1798</guid>
    </item>
  </channel>
</rss>
