62 Schools Hit by ERP Vulnerability Patched Months Ago

hacker with laptop

More than five dozen institutions have been victimized by a vulnerability in the Ellucian Banner products, which the company put out a patch for months ago. Federal Student Aid, an office of the U.S. Department of Education, took the unusual step of issuing a security alert warning that attackers could use the vulnerability to "log into the Banner system with an institutional account."

The office had identified 62 colleges and universities that had already been affected. Some had informed the office that attackers would exploit the opening and then use scripts in the admissions or enrollment section of the hacked system to create multiple student accounts, which would then be "leveraged almost immediately for criminal activity."

Ellucian responded with its own note, suggesting that the FSA alert referred to two problems. The first, the vulnerability, was addressed by a patch issued on May 14, 2019, and fixed in all subsequent software releases. The company specifically noted that the patch should only be applied to specific versions of software:

  • Banner Web Tailor versions 8.8.3 and 8.8.4; and
  • Banner Enterprise Identity Services versions 8.3, 8.3.1, 8.3.2, and 8.4 or earlier

Those schools concerned that they may have been victimized by the break-ins were advised to check their Banner 8.x self-service access logs "for unusual activity," such as a high number of error requests coming from the same IP address.

The second issue, involving the creation of fraudulent admission applications, was, said Ellucian, "an industry issue and not specific to Ellucian or Banner." Information about how to mitigate creation of fraudulent admissions applications was posted on the Ellucian community website, which sits behind a registration wall.

FSA also noted in its security alert that "in [its] shared mission with the institution to safeguard student information," it would like to hear from institutions that may have been affected.

Details about the vulnerability are part of the National Institute of Standards and Technology national vulnerability database.

Update: On Aug. 6, 2019, FSA issued an update. While the Department of Education is continuing to work with institutions "to determine what impact, if any, the Ellucian Banner System vulnerability may have had," the agency stated, "to date, based on reports from targeted institutions, we have not found any instances where ... the vulnerability has been exploited or is related to the issues described in the original alert."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Digital cyberspace with particles and Digital data

    Report: AI Is Moving Faster than Data Trust

    AI agents are already in use or pilot at most organizations, but data visibility, governance and precision recovery capabilities have not kept pace, according to Veeam's new Data & AI Trust Gap report.

  • Glowing route lines merging into single gold pathway

    Microsoft Merges Copilot Apps Into a Single User Experience

    Microsoft recently announced it is consolidating its consumer Copilot app and Microsoft 365 Copilot app into a single destination, addressing a fragmented product strategy that has required users to navigate separate applications for AI chat and productivity tools.

  • CIS Sandbox Tutor Eli Blouin at Bentley University imagines a future technology learning partner that supports curiosity, critical thinking, feedback, and personalized learning.

    Student Voices: Technology as a Future Learning Partner

    A data analytics and marketing major at Bentley University and a distinguished lecturer at the university explore the future of "technology learning partners" — technologies that participate in the learning process by asking questions and giving feedback, not just information search results.

  • Silhouettes of business professionals stand against a blurred futuristic city skyline at night, with a glowing digital network data connection

    It's Time for Higher Ed to Get Serious About AI Strategy

    Without a coordinated strategy that involves multiple academic and administrative units across the entire campus, colleges risk wasting resources, duplicating efforts, and ultimately failing to deliver on the promise of deploying technology to improve learning and operations.