SAP SLcM Fails to Conduct Proper Authorization Checks, Risking Escalation of Privileges
CVE-2024-42373
5.4MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 August 2024
What is CVE-2024-42373?
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the integrity of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Student Life Cycle Management (SLcM) 617
SAP Student Life Cycle Management (SLcM) 618
SAP Student Life Cycle Management (SLcM) 802