CVE-2014-6331

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:microsoft:active_directory_federation_services:2.1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:x64:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:microsoft:active_directory_federation_services:2.0:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_2008:r2:sp2:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_2008:*:sp2:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_2008:*:sp2:*:*:*:*:x86:*

Configuration 3 (hide)

AND
cpe:2.3:a:microsoft:active_directory_federation_services:3.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:x64:*:*

Information

Published : 2014-11-11 14:55

Updated : 2018-10-12 15:07


NVD link : CVE-2014-6331

Mitre link : CVE-2014-6331


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

microsoft

  • active_directory_federation_services
  • windows_server_2012
  • windows_2008