SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the integrity of the application.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap student Life Cycle Management |
|
CPEs | cpe:2.3:a:sap:student_life_cycle_management:617:*:*:*:*:*:*:* cpe:2.3:a:sap:student_life_cycle_management:618:*:*:*:*:*:*:* cpe:2.3:a:sap:student_life_cycle_management:802:*:*:*:*:*:*:* cpe:2.3:a:sap:student_life_cycle_management:803:*:*:*:*:*:*:* cpe:2.3:a:sap:student_life_cycle_management:804:*:*:*:*:*:*:* cpe:2.3:a:sap:student_life_cycle_management:805:*:*:*:*:*:*:* cpe:2.3:a:sap:student_life_cycle_management:806:*:*:*:*:*:*:* cpe:2.3:a:sap:student_life_cycle_management:807:*:*:*:*:*:*:* cpe:2.3:a:sap:student_life_cycle_management:808:*:*:*:*:*:*:* |
|
Vendors & Products |
Sap
Sap student Life Cycle Management |
Wed, 14 Aug 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 Aug 2024 05:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the integrity of the application. | |
Title | Missing Authorization Check in SAP Student Life Cycle Management (SLcM) | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-08-13T04:53:09.327Z
Updated: 2024-08-14T16:43:46.761Z
Reserved: 2024-07-31T04:09:36.223Z
Link: CVE-2024-42373
Vulnrichment
Updated: 2024-08-14T16:43:43.197Z
NVD
Status : Analyzed
Published: 2024-08-13T05:15:13.800
Modified: 2024-09-12T13:26:37.753
Link: CVE-2024-42373
Redhat
No data.