CVE-2015-7266: Iab Open Real-Time Bidding
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
The Interactive Advertising Bureau (IAB) OpenRTB 2.3 protocol implementation might allow remote attackers to conceal the status of ad transactions and potentially compromise bid integrity by leveraging failure to limit the time between bid responses and impression notifications, aka the Amnesia Bug.
Affected products
- Iab Open Real-Time Bidding: version 2.3 only
Published 2018-10-30. Last modified 2026-06-17.