Cross-site scripting (XSS) vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ellucian | banner_student | 8.5.1.2 |
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ellucian | banner_student | 8.7 |
| ellucian | banner_student | 8.6.1 |
| ellucian | banner_student | 8.6.6 |
| ellucian | banner_student | 8.6.2 |
| ellucian | banner_student | 8.6.5 |
| ellucian | banner_student | 8.6.7 |
| ellucian | banner_student | 8.6.3 |
| ellucian | banner_student | 8.5.1.2 |
| ellucian | banner_student | 8.6.4 |
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-640,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ellucian | banner_student | 8.7 |
| ellucian | banner_student | 8.6.1 |
| ellucian | banner_student | 8.6.6 |
| ellucian | banner_student | 8.6.2 |
| ellucian | banner_student | 8.6.5 |
| ellucian | banner_student | 8.6.7 |
| ellucian | banner_student | 8.5.1.2 |
| ellucian | banner_student | 8.6.3 |
| ellucian | banner_student | 8.6.4 |
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ellucian | banner_student | 8.6.1 |
| ellucian | banner_student | 8.7 |
| ellucian | banner_student | 8.6.6 |
| ellucian | banner_student | 8.6.2 |
| ellucian | banner_student | 8.6.5 |
| ellucian | banner_student | 8.6.7 |
| ellucian | banner_student | 8.6.3 |
| ellucian | banner_student | 8.5.1.2 |
| ellucian | banner_student | 8.6.4 |
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session (and cause a denial of service) by repeatedly requesting the initial Banner Web Tailor main page with the IDMSESSID cookie set to the victim's UDCID, which in the case tested is the institutional ID. During a login attempt by a victim, the attacker can leverage the race condition and will be issued the SESSID that was meant for this victim.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ellucian | banner_web_tailor | 8.8.3 |
| ellucian | banner_enterprise_identity_services | 8.3 |
| ellucian | banner_enterprise_identity_services | 8.3.2 |
| ellucian | banner_enterprise_identity_services | 8.4 |
| ellucian | banner_enterprise_identity_services | 8.3.1 |
| ellucian | banner_web_tailor | 8.9 |
| ellucian | banner_web_tailor | 8.8.4 |