CVE-2019-8978
Description
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session (and cause a denial of service) by repeatedly requesting the initial Banner Web Tailor main page with the IDMSESSID cookie set to the victim's UDCID, which in the case tested is the institutional ID. During a login attempt by a victim, the attacker can leverage the race condition and will be issued the SESSID that was meant for this victim.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Ellucian/Banner Web Tailor and Banner Enterprise Identity Servicesdescription
- Range: 8.8.3, 8.8.4, 8.9
- Range: 8.3, 8.3.1, 8.3.2, 8.4
Patches
Vulnerability mechanics
References
6- packetstormsecurity.com/files/152856/Ellucian-Banner-Web-Tailor-Banner-Enterprise-Identity-Services-Improper-Authentication.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2019/May/18nvdMailing ListThird Party Advisory
- raw.githubusercontent.com/JoshuaMulliken/CVE-2019-8978/master/README.txtnvdThird Party Advisory
- seclists.org/bugtraq/2019/May/31nvdMailing ListThird Party Advisory
- ecommunities.ellucian.com/message/252749nvdPermissions Required
- ecommunities.ellucian.com/message/252810nvdPermissions Required
News mentions
0No linked articles in our index yet.