Critical severity9.8NVD Advisory· Published Mar 28, 2017· Updated May 13, 2026
CVE-2016-9125
CVE-2016-9125
Description
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for an attacker to steal an authenticated session.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/revive-adserver/revive-adserver/commit/4910365631eabbb208961c36149f41cc8159fb39nvdIssue TrackingPatchThird Party Advisory
- www.revive-adserver.com/security/revive-sa-2016-001/nvdPatchVendor Advisory
- hackerone.com/reports/93809nvdPermissions Required
- hackerone.com/reports/93813nvdPermissions Required
News mentions
0No linked articles in our index yet.