Information disclosure vulnerability in Active Directory Federation Services while logging off a userID: oval:org.secpod.oval:def:24080 | Date: (C)2015-04-15 (M)2021-09-11 |
Class: VULNERABILITY | Family: windows |
The host is installed with Active Directory Federation Services 3.0 and is prone to an information disclosure vulnerability. A flaw is present in the application, which fails to properly log off an user. Successful exploitation could allow attackers to discover information to which an AD FS user has access.
Platform: |
Microsoft Windows Server 2012 R2 |
Product: |
Microsoft Active Directory Federation Services |