CVE-2023-1632

** DISPUTED ** A vulnerability has been found in Ellucian Banner Web Tailor 8.6 and classified as critical. This vulnerability affects unknown code of the file /PROD_ar/twbkwbis.P_FirstMenu of the component Login Page. The manipulation of the argument PIDM/WEBID leads to improper authorization. The attack can be initiated remotely. After submitting proper login credentials it becomes possible to generate new valid session identifiers on the OTP page. The real existence of this vulnerability is still doubted at the moment. VDB-224014 is the identifier assigned to this vulnerability.
References
Link Resource
https://vuldb.com/?ctiid.224014 Permissions Required Third Party Advisory
https://vuldb.com/?id.224014 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ellucian:banner_web_tailor:8.6:*:*:*:*:*:*:*

History

30 Mar 2023, 19:50

Type Values Removed Values Added
References (MISC) https://vuldb.com/?ctiid.224014 - (MISC) https://vuldb.com/?ctiid.224014 - Permissions Required, Third Party Advisory
References (MISC) https://vuldb.com/?id.224014 - (MISC) https://vuldb.com/?id.224014 - Permissions Required, Third Party Advisory
CWE CWE-862
First Time Ellucian
Ellucian banner Web Tailor
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:ellucian:banner_web_tailor:8.6:*:*:*:*:*:*:*

25 Mar 2023, 21:15

Type Values Removed Values Added
Summary A vulnerability has been found in Ellucian Banner Web Tailor 8.6 and classified as critical. This vulnerability affects unknown code of the file /PROD_ar/twbkwbis.P_FirstMenu of the component Login Page. The manipulation of the argument PIDM/WEBID leads to improper authorization. The attack can be initiated remotely. After submitting proper login credentials it becomes possible to generate new valid session identifiers on the OTP page. VDB-224014 is the identifier assigned to this vulnerability. ** DISPUTED ** A vulnerability has been found in Ellucian Banner Web Tailor 8.6 and classified as critical. This vulnerability affects unknown code of the file /PROD_ar/twbkwbis.P_FirstMenu of the component Login Page. The manipulation of the argument PIDM/WEBID leads to improper authorization. The attack can be initiated remotely. After submitting proper login credentials it becomes possible to generate new valid session identifiers on the OTP page. The real existence of this vulnerability is still doubted at the moment. VDB-224014 is the identifier assigned to this vulnerability.

25 Mar 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-25 17:15

Updated : 2023-03-30 19:50


NVD link : CVE-2023-1632

Mitre link : CVE-2023-1632


JSON object : View

Products Affected

ellucian

  • banner_web_tailor
CWE
CWE-862

Missing Authorization