HIGH

CVE-2019-8978

CVSS v3

8.1

HIGH

EPSS Score

12.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session (and cause a denial of service) by repeatedly requesting the initial Banner Web Tailor main page with the IDMSESSID cookie set to the victim's UDCID, which in the case tested is the institutional ID. During a login attempt by a victim, the attacker can leverage the race condition and will be issued the SESSID that was meant for this victim.

Technical details

Published
5/14/2019

Frequently asked questions

What is CVE-2019-8978?

An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session (and cause a denial of service) by repeatedly requesting the initial Banner Web Tailor main page with the IDMSESSID cookie set to the victim's UDCID, which in the case tested is the institutional ID. During a login attempt by a victim, the attacker can leverage the race condition and will be issued the SESSID that was meant for this victim.

Is CVE-2019-8978 actively exploited?

Active exploitation of CVE-2019-8978 has not been confirmed. The EPSS score is 12.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-8978?

CVE-2019-8978 has a CVSS v3 base score of 8.1 (HIGH severity).

Is CVE-2019-8978 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.