Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23gf-62w7-q77v

Опубликовано: 11 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to access and edit non-sensitive report variants that are typically restricted, causing minimal impact on the confidentiality and integrity of the application.

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to access and edit non-sensitive report variants that are typically restricted, causing minimal impact on the confidentiality and integrity of the application.

EPSS

Процентиль: 47%
0.00242
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.4
nvd
около 1 года назад

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to access and edit non-sensitive report variants that are typically restricted, causing minimal impact on the confidentiality and integrity of the application.

CVSS3: 5.4
fstec
больше 1 года назад

Уязвимость системы управления жизненным циклом студентов в высших учебных заведениях SAP Student Life Cycle Management (SLcM), связанная с недостатками процедуры авторизации, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 47%
0.00242
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862