CVE-2015-7371: Medium severity revive adserver vulnerability
Published Oct 14, 2015
·Updated
Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption) via a direct request.
Affected Software
1 affected component
revive-adserver Revive Adserver<=3.2.1
Event History
Oct 14, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7371?
CVE-2015-7371 is classified as a moderate severity vulnerability due to its potential for denial of service.
2
How do I fix CVE-2015-7371?
To fix CVE-2015-7371, upgrade Revive Adserver to version 3.2.2 or later.
3
What causes CVE-2015-7371?
CVE-2015-7371 is caused by the lack of access restrictions to run-mpe.php in Revive Adserver.
4
Who is affected by CVE-2015-7371?
Any user running Revive Adserver versions before 3.2.2 is affected by CVE-2015-7371.
5
What are the risks associated with CVE-2015-7371?
The risks associated with CVE-2015-7371 include potential denial of service due to resource consumption.