PT-2018-4407 · Iab · Openrtb

Published

2018-10-30

·

Updated

2019-01-29

·

CVE-2015-7266

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IAB OpenRTB version 2.3
Description The issue concerns the Interactive Advertising Bureau (IAB) OpenRTB 2.3 protocol implementation, which might allow remote attackers to conceal the status of ad transactions and potentially compromise bid integrity. This is due to the failure to limit the time between bid responses and impression notifications.
Recommendations For IAB OpenRTB version 2.3, consider implementing time limits between bid responses and impression notifications to prevent exploitation of this issue. As a temporary workaround, restrict access to bid transaction status to minimize the risk of bid integrity compromise.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7266

Affected Products

Openrtb