CVE-2015-7367: High severity revive adserver vulnerability
Published Oct 14, 2015
·Updated
Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) deleted or (2) unlinked.
Affected Software
1 affected component
revive-adserver Revive Adserver<=3.2.1
Event History
Oct 14, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7367?
CVE-2015-7367 is categorized as a medium severity vulnerability due to its potential for unauthorized actions via unexpired sessions.
2
How do I fix CVE-2015-7367?
To fix CVE-2015-7367, upgrade to Revive Adserver version 3.2.2 or later.
3
What types of attacks are possible with CVE-2015-7367?
CVE-2015-7367 allows remote attackers to perform actions on behalf of deleted or unlinked users.
4
Which versions of Revive Adserver are affected by CVE-2015-7367?
CVE-2015-7367 affects all versions of Revive Adserver prior to 3.2.2.
5
What should I do if I cannot immediately upgrade to fix CVE-2015-7367?
If immediate upgrading is not possible, limit user access and monitor session activity to mitigate the risks associated with CVE-2015-7367.