Assigner | sap |
Reserved | 2024-05-07 |
Published | 2024-06-11 |
Updated | 2024-06-11 |
Description
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to access and edit non-sensitive report variants that are typically restricted, causing minimal impact on the confidentiality and integrity of the application.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Problem types
CWE-862: Missing Authorization
Product status
IS-PS-CA 617
618
802
803
804
805
806
807
808
References
https://me.sap.com/notes/3457265
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html