Lucene search

K
cve[email protected]CVE-2014-6331
HistoryNov 11, 2014 - 10:55 p.m.

CVE-2014-6331

2014-11-1122:55:05
CWE-264
web.nvd.nist.gov
24
cve-2014-6331
microsoft
active directory federation services
ad fs
saml
vulnerability
information disclosure
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.3%

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation, aka “Active Directory Federation Services Information Disclosure Vulnerability.”

Affected configurations

NVD
Node
microsoftactive_directory_federation_servicesMatch2.1
AND
microsoftwindows_server_2012x64
Node
microsoftactive_directory_federation_servicesMatch2.0
AND
microsoftwindows_2008sp2x64
OR
microsoftwindows_2008sp2x86
OR
microsoftwindows_2008Matchr2sp2x64
Node
microsoftactive_directory_federation_servicesMatch3.0
AND
microsoftwindows_server_2012Matchr2x64

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.3%