CVE-2019-8978 is an improper authentication vulnerability affecting Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9, and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, when used in conjunction with SSO Manager. The flaw arises from a race condition in session handling during the login flow. A remote attacker can repeatedly request the initial Banner Web Tailor page or the P_VerifyID/P_VerifyId endpoint while supplying an IDMSESSID cookie set to a victim's UDCID (reported in testing as the institutional ID). If timed to coincide with the victim's login attempt, the application may issue the attacker the SESSID intended for the victim. This results in session hijacking due to improper authentication and session binding, and can also disrupt the victim's login process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An improper authentication (broken authentication) vulnerability caused by a race condition when used with SSO Manager, affecting Ellucian Banner Web Tailor and Banner Enterprise Identity Services; can allow authentication bypass under certain conditions.
A high-severity improper authentication vulnerability in Ellucian Banner Web Tailor and Banner Enterprise Identity Services, caused by a race condition in SSO Manager, allowing remote attackers to hijack user sessions and potentially cause denial of service.
A race condition vulnerability in Ellucian Banner Web Tailor allows attackers to exploit the P_VerifyId endpoint by flooding it with requests, potentially enabling session hijacking via the IDMSESSID cookie.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.