PT-2006-1576 · Blackboard · Blackboard Academic Suite
Published
2006-02-01
·
Updated
2024-08-07
·
CVE-2006-0511
CVSS v2.0
4.3
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Blackboard Academic Suite versions 6.0 and earlier
Description
The issue arises when the software does not properly clear session information after a user has been idle and then de-authenticates. This allows subsequent users to log in as the previous user, potentially gaining privileges. The vendor has disputed this issue, stating it is related to a customer's specific Kerberos authentication single sign-on application rather than a vulnerability in the Blackboard product itself.
Recommendations
For Blackboard Academic Suite versions 6.0 and earlier, consider implementing additional session management measures to ensure proper clearance of user session information upon de-authentication. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blackboard Academic Suite