SAP SLcM Fails to Conduct Proper Authorization Checks, Risking Escalation of Privileges

CVE-2024-42373
5.4MEDIUM

Key Information

Vendor
SAP
Status
SAP Student Life Cycle Management (slcm)
Vendor
CVE Published:
13 August 2024

Summary

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the integrity of the application.

Affected Version(s)

SAP Student Life Cycle Management (SLcM) = 617

SAP Student Life Cycle Management (SLcM) = 618

SAP Student Life Cycle Management (SLcM) = 802

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.