PT-2018-4407 · Iab · Openrtb
Published
2018-10-30
·
Updated
2019-01-29
·
CVE-2015-7266
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IAB OpenRTB version 2.3
Description
The issue concerns the Interactive Advertising Bureau (IAB) OpenRTB 2.3 protocol implementation, which might allow remote attackers to conceal the status of ad transactions and potentially compromise bid integrity. This is due to the failure to limit the time between bid responses and impression notifications.
Recommendations
For IAB OpenRTB version 2.3, consider implementing time limits between bid responses and impression notifications to prevent exploitation of this issue. As a temporary workaround, restrict access to bid transaction status to minimize the risk of bid integrity compromise.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openrtb