CVE-2015-7369: High severity revive adserver vulnerability
Published Oct 14, 2015
·Updated
The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.
Affected Software
1 affected component
revive-adserver Revive Adserver<=3.2.1
Event History
Oct 14, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7369?
CVE-2015-7369 is considered to have a high severity due to the potential for cross-domain attacks.
2
How do I fix CVE-2015-7369?
To fix CVE-2015-7369, upgrade Revive Adserver to version 3.2.2 or later.
3
What type of attacks can CVE-2015-7369 allow?
CVE-2015-7369 allows remote attackers to conduct cross-domain attacks through unrestricted access in the default Flash cross-domain policy.
4
Which versions of Revive Adserver are affected by CVE-2015-7369?
CVE-2015-7369 affects all versions of Revive Adserver prior to 3.2.2.
5
Is CVE-2015-7369 related to permissions in Flash applications?
Yes, CVE-2015-7369 is related to inadequate restrictions in the Flash cross-domain policy file, which can lead to unauthorized access.