Description
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username.
Published: 2017-03-28
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-9946 Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username.
History

No history.

Subscriptions

Revive-adserver Revive Adserver
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-08-06T02:42:10.602Z

Reserved: 2016-10-31T00:00:00.000Z

Link: CVE-2016-9129

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-03-28T02:59:00.527

Modified: 2025-04-20T01:37:25.860

Link: CVE-2016-9129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses