CVE-2019-8978observed exploitation

CVE-2019-8978

Published · Updated

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 5.9%
from disclosure to weapon
Published on NVDMay 14
VulnCheck+66d
exploitation probability
5.9%top 7% of all CVEs
observed exploitation
yesVulnCheck
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session (and cause a denial of service) by repeatedly requesting the initial Banner Web Tailor main page with the IDMSESSID cookie set to the victim's UDCID, which in the case tested is the institutional ID. During a login attempt by a victim, the attacker can leverage the race condition and will be issued the SESSID that was meant for this victim.
Affected products
n/a · n/a