If not addressed soon, students might be able to change grades

Sep 16, 2011 09:53 GMT  ·  By

Blackboard Learn, one of the most used educational platforms in the world, was recently discovered as being insecure because of multiple vulnerabilities that could expose sensitive information to unauthorized parties.

The platform is implemented by schools and universities all over the world, being utilized even by the U.S Military to educate their soldiers.

According to SC Magazine, Australian universities might have been the ones to detect the flaws. At first, Blackboard Learn didn't respond to these problems as expected and only after AusCERT learned of the matter and threatened the company, measures were taken to patch up the holes existent in their product.

The vulnerabilities seem to be caused by the improper configuration of the web application and other issues that were supposed to be fixed in the later versions of the software.

Stephanie Tan, security director of the company owning the platform, told SC Magazine that the exploit possibilities were not considered to be critical and no institutions were compromised because of them.

“Many of these issues are common issues associated with any type of web application or software, and all of the issues will be addressed through existing patches and planned releases,” she revealed.

However, these answers were not reassuring to university IT managers who grew more and more concerned about the possible effects these weak points might have.

Now, after being persuaded by AusCERT, Blackboard Learn claims that they only have one remaining issue they have to address and they are currently working on it in close collaboration with the institution that discovered it.

“We issued a support bulletin to Blackboard Learn clients today after completing our review of the issues. The bulletin includes information about how the issues are being addressed through existing patches and planned releases, as well as recommendations for general security management and best practices,” company officials revealed in a statement.