CVE-2015-7266

The Interactive Advertising Bureau (IAB) OpenRTB 2.3 protocol implementation might allow remote attackers to conceal the status of ad transactions and potentially compromise bid integrity by leveraging failure to limit the time between bid responses and impression notifications, aka the Amnesia Bug.
References
Link Resource
http://media.pixalate.com/white-papers/xindi.pdf Exploit Mitigation Third Party Advisory
http://media.pixalate.com/white-papers/xindi.pdf Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:iab:open_real-time_bidding:2.3:*:*:*:*:*:*:*

History

21 Nov 2024, 02:36

Type Values Removed Values Added
References () http://media.pixalate.com/white-papers/xindi.pdf - Exploit, Mitigation, Third Party Advisory () http://media.pixalate.com/white-papers/xindi.pdf - Exploit, Mitigation, Third Party Advisory

Information

Published : 2018-10-30 17:29

Updated : 2024-11-21 02:36


NVD link : CVE-2015-7266

Mitre link : CVE-2015-7266

CVE.ORG link : CVE-2015-7266


JSON object : View

Products Affected

iab

  • open_real-time_bidding
CWE
CWE-264

Permissions, Privileges, and Access Controls