CVE-2019-8978
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.86%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session (and cause a denial of service) by repeatedly requesting the initial Banner Web Tailor main page with the IDMSESSID cookie set to the victim's UDCID, which in the case tested is the institutional ID. During a login attempt by a victim, the attacker can leverage the race condition and will be issued the SESSID that was meant for this victim.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.86% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287, CWE-362
- Affected
- ellucian/banner enterprise identity services · ellucian/banner web tailor
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/152856/Ellucian-Banner-Web-Tailor-Banner-Enterprise-Identity-Services-Improper-Authentication.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/May/18Mailing List, Third Party Advisory
- https://ecommunities.ellucian.com/message/252749#252749Permissions Required
- https://ecommunities.ellucian.com/message/252810#252810Permissions Required
- https://raw.githubusercontent.com/JoshuaMulliken/CVE-2019-8978/master/README.txtThird Party Advisory
- https://seclists.org/bugtraq/2019/May/31Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152856/Ellucian-Banner-Web-Tailor-Banner-Enterprise-Identity-Services-Improper-Authentication.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/May/18Mailing List, Third Party Advisory
- https://ecommunities.ellucian.com/message/252749#252749Permissions Required
- https://ecommunities.ellucian.com/message/252810#252810Permissions Required
- https://raw.githubusercontent.com/JoshuaMulliken/CVE-2019-8978/master/README.txtThird Party Advisory
- https://seclists.org/bugtraq/2019/May/31Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.