Improper Authentication Management in Revive Adserver by Revive
CVE-2016-9124
What is CVE-2016-9124?
Revive Adserver versions prior to 3.2.3 are susceptible to improper authentication management that allows password-guessing attacks on the login page. While an account lockdown feature was considered for better security, it was ultimately deemed disruptive for legitimate users during attack scenarios. To mitigate these risks, a random delay was implemented after failed password attempts, along with measures to prevent simultaneous brute-force attempts, ensuring that valid users are still able to access the adserver during ongoing attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Revive Adserver All before 3.2.3 Revive Adserver All versions before 3.2.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
