CVE-2014-6331

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:microsoft:active_directory_federation_services:2.1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:x64:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:microsoft:active_directory_federation_services:2.0:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_2008:*:sp2:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_2008:*:sp2:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_2008:r2:sp2:*:*:*:*:x64:*

Configuration 3 (hide)

AND
cpe:2.3:a:microsoft:active_directory_federation_services:3.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:x64:*:*

History

No history.

Information

Published : 2014-11-11 22:55

Updated : 2024-02-04 18:35


NVD link : CVE-2014-6331

Mitre link : CVE-2014-6331

CVE.ORG link : CVE-2014-6331


JSON object : View

Products Affected

microsoft

  • windows_2008
  • windows_server_2012
  • active_directory_federation_services
CWE
CWE-264

Permissions, Privileges, and Access Controls