CVE-2016-9125

9.8 CRITICAL
Published: March 28, 2017 Modified: May 13, 2026
View on NVD

Description

Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for an attacker to steal an authenticated session.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/revive-adserver/revive-adserver/commit/4910365631eabbb208961c36149f41cc8159fb39
Source: support@hackerone.com
Issue Tracking Patch Third Party Advisory
https://hackerone.com/reports/93809
Source: support@hackerone.com
Permissions Required
https://hackerone.com/reports/93813
Source: support@hackerone.com
Permissions Required
https://www.revive-adserver.com/security/revive-sa-2016-001/
Source: support@hackerone.com
Patch Vendor Advisory
https://github.com/revive-adserver/revive-adserver/commit/4910365631eabbb208961c36149f41cc8159fb39
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Patch Third Party Advisory
https://hackerone.com/reports/93809
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
https://hackerone.com/reports/93813
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
https://www.revive-adserver.com/security/revive-sa-2016-001/
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
9.8 / 10.0
EPSS (Exploit Probability)
2.7%
84th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

revive-adserver