Ellucian is the primary vendor of student information and enterprise identity management systems serving higher education institutions, with its vulnerabilities concentrating in widely deployed products such as Banner Student, Banner Enterprise Identity Services, and Ethos Identity. The vendor's disclosures skew toward serious outcomes and frequently acquire public exploit code, while exposures recur through access-control and authentication weaknesses—including authorization bypass, race conditions, and improper input handling—that reflect the sensitivity and complexity of identity and data-access layers in education platforms. Defenders managing Ellucian deployments should prioritize patching and restrict network access to these systems; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ellucian over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2822MEDIUM A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation | May 20, 2023 | 6.1 | 31 | NO | YES |
CVE-2015-4689CRITICAL Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset." | Sep 11, 2017 | 9.8 | 24 | NO | NO |
CVE-2019-8978HIGH An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Se | May 14, 2019 | 8.1 | 22 | NO | NO |
CVE-2023-49339MEDIUM Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint. | Feb 13, 2024 | 6.5 | 20 | NO | NO |
CVE-2015-5054MEDIUM Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing | Sep 11, 2017 | 6.1 | 17 | NO | NO |
CVE-2015-4687MEDIUM Cross-site scripting (XSS) vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vector | Sep 11, 2017 | 6.1 | 17 | NO | NO |
CVE-2015-4688MEDIUM Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests. | Sep 11, 2017 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ellucian.
Media articles that mention a CVE ID that affects a product developed by Ellucian — matched by CVE ID, not by vendor name.