CVE-2024-42373: SAP Student Life Cycle Management
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the integrity of the application.
Affected products
- SAP Student Life Cycle Management: version 617 only; version 618 only; version 802 only; version 803 only; version 804 only; version 805 only; …
Published 2024-08-13. Last modified 2026-06-17.