Revive Adserver before 3.2.2 does not send the appropriate Cache-Control HTTP headers in responses for admin UI pages, which allows local users to obtain sensitive information via the web browser cache.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.