Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username.
Advisories
Source ID Title
EUVD EUVD EUVD-2016-9946 Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-08-06T02:42:10.602Z

Reserved: 2016-10-31T00:00:00

Link: CVE-2016-9129

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-03-28T02:59:00.527

Modified: 2025-04-20T01:37:25.860

Link: CVE-2016-9129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.