SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to access and edit non-sensitive report variants that are typically restricted, causing minimal impact on the confidentiality and integrity of the application.
History

Fri, 09 Aug 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap student Life Cycle Management
CPEs cpe:2.3:a:sap:student_life_cycle_management:618:*:*:*:*:*:*:*
cpe:2.3:a:sap:student_life_cycle_management:802:*:*:*:*:*:*:*
cpe:2.3:a:sap:student_life_cycle_management:803:*:*:*:*:*:*:*
cpe:2.3:a:sap:student_life_cycle_management:804:*:*:*:*:*:*:*
cpe:2.3:a:sap:student_life_cycle_management:805:*:*:*:*:*:*:*
cpe:2.3:a:sap:student_life_cycle_management:806:*:*:*:*:*:*:*
cpe:2.3:a:sap:student_life_cycle_management:807:*:*:*:*:*:*:*
cpe:2.3:a:sap:student_life_cycle_management:808:*:*:*:*:*:*:*
cpe:2.3:a:sap:student_life_cycle_management:is-ps-ca_617:*:*:*:*:*:*:*
Vendors & Products Sap
Sap student Life Cycle Management

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2024-06-11T02:17:13.787Z

Updated: 2024-08-02T02:59:21.880Z

Reserved: 2024-05-07T05:46:11.658Z

Link: CVE-2024-34690

cve-icon Vulnrichment

Updated: 2024-08-02T02:59:21.880Z

cve-icon NVD

Status : Modified

Published: 2024-06-11T03:15:11.547

Modified: 2024-11-21T09:19:12.217

Link: CVE-2024-34690

cve-icon Redhat

No data.