Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: microsoft

Published: 2014-11-11T22:00:00

Updated: 2018-10-12T19:57:01

Reserved: 2014-09-11T00:00:00


Link: CVE-2014-6331

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2014-11-11T22:55:05.153

Modified: 2018-10-12T22:07:34.770


Link: CVE-2014-6331

JSON object: View

cve-icon Redhat Information

No data.

CWE