Lucene search

K
nvd[email protected]NVD:CVE-2014-6331
HistoryNov 11, 2014 - 10:55 p.m.

CVE-2014-6331

2014-11-1122:55:05
CWE-264
web.nvd.nist.gov
3

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

74.2%

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation, aka “Active Directory Federation Services Information Disclosure Vulnerability.”

Affected configurations

Nvd
Node
microsoftactive_directory_federation_servicesMatch2.1
AND
microsoftwindows_server_2012x64
Node
microsoftactive_directory_federation_servicesMatch2.0
AND
microsoftwindows_2008sp2x64
OR
microsoftwindows_2008sp2x86
OR
microsoftwindows_2008Matchr2sp2x64
Node
microsoftactive_directory_federation_servicesMatch3.0
AND
microsoftwindows_server_2012Matchr2x64
VendorProductVersionCPE
microsoftactive_directory_federation_services2.1cpe:2.3:a:microsoft:active_directory_federation_services:2.1:*:*:*:*:*:*:*
microsoftwindows_server_2012*cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:x64:*:*
microsoftactive_directory_federation_services2.0cpe:2.3:a:microsoft:active_directory_federation_services:2.0:*:*:*:*:*:*:*
microsoftwindows_2008*cpe:2.3:o:microsoft:windows_2008:*:sp2:*:*:*:*:x64:*
microsoftwindows_2008*cpe:2.3:o:microsoft:windows_2008:*:sp2:*:*:*:*:x86:*
microsoftwindows_2008r2cpe:2.3:o:microsoft:windows_2008:r2:sp2:*:*:*:*:x64:*
microsoftactive_directory_federation_services3.0cpe:2.3:a:microsoft:active_directory_federation_services:3.0:*:*:*:*:*:*:*
microsoftwindows_server_2012r2cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:x64:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

74.2%