CVE Published: 13/08/2024 |
CVE Updated: 14/08/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP Student Life Cycle Management (SLcM) Status : PUBLISHED
CVE-2024-42373 Description
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the integrity of the application.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N