iTnews
  • Home
  • News
  • Technology
  • Security

Blackboard e-learning platform exposes student data

By Darren Pauli
Sep 19 2011 11:33AM
Follow google news

Zero-day vulnerabiilties expose millions of student exams, tests and data.

Multiple zero-day security vulnerabilities have been found in the world’s most popular educational software - holes that allow students to change grades and download unpublished exams, whilst allowing criminals to steal personal information.

Blackboard e-learning platform exposes student data

Vulnerabilities in the Blackboard Learn platform have the potential to affect millions of school and university students and thousands of institutions around the world.

The platform is used by the United States military to train soliders.

After several weeks of investigation by university IT managers, security professionals and iTnews' sister publication SC Magazine, Blackboard Learn has acknowledged it is sending a security advisory to customers to address the issue.

Penetration tests

Sources within Australia's university sector, talking to SC Magazine on condition of anonymity, believe they may have been first to discover the security holes.

One Australian university, which declined to be named for this story, recruited penetration testing company Securus Global to ethically hack the software.

The security company said its policy was to not disclose any information about clients.

But sources said that during tests of the Blackboard software, security professionals had gained administrative access to databases in which student exams, assignments and grades were stored. Personal information stored on students was also accessible.

The problems relate to default configuration and web application  vulnerabilities present in all versions of the Blackboard Learn system. The latest version of the platform was thought to make exploitation slightly more difficult, but did not rectify the problems.

University IT managers said they believed most schools and  universities using Blackboard would operate the outdated and more  vulnerable systems.

Upon SC Magazine's initial investigations, Blackboard Learn security director Stephanie Tan said   the vulnerabilities examined were at that point not “highly critical”.

“We are not aware of any institution’s academic or student data having been compromised in any way by these issues,” Tan said.

“Many of these issues are common issues associated with any type of web application or software, and all of the issues will be addressed through existing patches and planned releases.”

But she confirmed the vulnerabilities would remain unpatched until the first service pack update is delivered “prior to the end of the year”, Tan said.

The company claimed in a statement that "there have been no incidents of academic or student data being exposed in any way by" the vulnerabilities.

University IT managers said they would not be able to wait. They became concerned that they would be forced to  shut down the systems, disrupting distance and online courses, should  the holes be exploited.

Several advised Blackboard Learn of the holes and sought  further information on the vulnerabilities.

They claim their requests fell on deaf ears for more than a month.

“They didn’t want to know about it, which quite frankly, I couldn’t believe,” one IT manager of a major university said. “I was stunned.”

Blackboard refuted claims it ignored customer requests for information and said it "remained in constant communication with clients since the day the issue was initially logged (in July) to our client support team."

But customers said that after weeks of failed attempts to gain information from Blackboard, the problem was escalated to AusCERT, a non-profit security organisation funded by Queensland University.

The industry heavyweight warned Blackboard it would publish an advisory to the Australian security industry and its global network of Computer Emergency Response Teams.

A security advisor at Blackboard, believed to be a different employee than the case handler in the initial round of communication with customers, quickly responded and promised the holes would be addressed.

AusCERT declined to comment for this story, but confirmed it had an advisory ready to be issued.

Response

Blackboard Learn said it would issue an advisory today to universities in response.

“We issued a support bulletin to Blackboard Learn clients today after completing our review of the issues. The bulletin includes information about how the issues are being addressed through existing patches and planned releases, as well as recommendations for general security management and best practices,” the company said in a statement.

“The majority of the issues were known issues responsibly reported by other institutions and security researchers, and for which Blackboard has commenced remediation for release to the larger client base as part of our standard operating procedure.”

Blackboard said it strove “to be vigilant at building security into its products and providing prompt and carefully tested product updates”.

“When Blackboard learns of any potential vulnerability, we investigate the issue and establish a resolution plan as part of our standard procedure.”

The company said one vulnerability remained to be investigated.

“We are completing our investigation on one remaining issue in collaboration with the institutions who reported it.”

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:
blackboardexploitspenetration testingsecurityuniversitiesvulnerabilitieszeroday

Related Articles

  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
Join our WhatsApp Channel

Partner Content

CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
AI is delivering business value today
Partner Content AI is delivering business value today
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.