CVE-2024-34690: SAP Student Life Cycle Management

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to access and edit non-sensitive report variants that are typically restricted, causing minimal impact on the confidentiality and integrity of the application.

Affected products

  • SAP Student Life Cycle Management: version 618 only; version 802 only; version 803 only; version 804 only; version 805 only; version 806 only; …

Published 2024-06-11. Last modified 2026-06-17.