CVE-2024-45284

LOW

SAP Student Life Cycle Management - Authenticated Privilege Escalation via Unrestricted SLCM Transaction Functions

Title source: llm
STIX 2.1

Description

An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricted. This may result in an escalation of privileges causing low impact on integrity of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 2.4
EPSS 0.0008
EPSS Percentile 22.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (10)
SAP_SE/SAP Student Life Cycle Management (SLcM) 617
SAP_SE/SAP Student Life Cycle Management (SLcM) 618
SAP_SE/SAP Student Life Cycle Management (SLcM) 800
SAP_SE/SAP Student Life Cycle Management (SLcM) 802
SAP_SE/SAP Student Life Cycle Management (SLcM) 803
SAP_SE/SAP Student Life Cycle Management (SLcM) 804
SAP_SE/SAP Student Life Cycle Management (SLcM) 805
SAP_SE/SAP Student Life Cycle Management (SLcM) 806
SAP_SE/SAP Student Life Cycle Management (SLcM) 807
SAP_SE/SAP Student Life Cycle Management (SLcM) 808
Published Sep 10, 2024
Tracked Since Feb 18, 2026