CVE-2024-42373: Missing Authorization Check in SAP Student Life Cycle Management (SLcM)
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42373?
CVE-2024-42373 has a medium severity level due to its potential to allow privilege escalation in SAP Student Life Cycle Management.
How do I fix CVE-2024-42373?
To fix CVE-2024-42373, apply the latest security patches and updates provided by SAP for affected versions of Student Life Cycle Management.
What versions of SAP Student Life Cycle Management are affected by CVE-2024-42373?
CVE-2024-42373 affects SAP Student Life Cycle Management versions 617, 618, 802, 803, 804, 805, 806, 807, and 808.
What kind of issues can exploiting CVE-2024-42373 cause?
Exploiting CVE-2024-42373 could allow an attacker to delete non-sensitive report variants, leading to potential data integrity issues.
Who should be concerned about CVE-2024-42373?
Organizations using the affected versions of SAP Student Life Cycle Management should be concerned about CVE-2024-42373 due to the risk of unauthorized actions by authenticated users.