Description
Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This leads to low impact on confidentiality and no effect on integrity or availability.
Published: 2026-02-10
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing authorization check in the Balanced Scorecard component of SAP Strategic Enterprise Management’s Business Server Pages. An authenticated user can view data that they should not have access to, creating a modest breach of confidentiality while leaving integrity and availability unaffected.

Affected Systems

This flaw affects SAP Strategic Enterprise Management as identified by SAP SE, covering versions 600, 602, 603, 604, 605, 634, 700, 736, 746, 747, 748, and 800. The issue resides in the Balanced Scorecard web application delivered via Business Server Pages.

Risk and Exploitability

With a CVSS score of 4.3 the overall severity is considered low. The EPSS score of less than 1% reflects a very low likelihood of actual exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a legitimate user account with access to the application; the attacker can exploit the missing check by using their standard credentials to request privileged data via the web interface.

Generated by OpenCVE AI on April 17, 2026 at 20:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch referenced in SAP note 3680390 or through the SAP Security Patch Day release
  • After patching, review user role assignments to ensure least‑privilege access for the Balanced Scorecard component
  • Monitor application logs for anomalies such as repeated access to restricted data outside normal user patterns

Generated by OpenCVE AI on April 17, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap strategic Enterprise Management
CPEs cpe:2.3:a:sap:strategic_enterprise_management:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:602:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:603:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:604:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:605:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:634:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:736:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:746:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:748:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:800:*:*:*:*:*:*:*
Vendors & Products Sap
Sap strategic Enterprise Management

Tue, 10 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Feb 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Strategic Enterprise Management (balanced Scorecard In Bsp Application)
Vendors & Products Sap Se
Sap Se sap Strategic Enterprise Management (balanced Scorecard In Bsp Application)

Tue, 10 Feb 2026 03:45:00 +0000

Type Values Removed Values Added
Description Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This leads to low impact on confidentiality and no effect on integrity or availability.
Title Missing Authorization Check in SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Sap Strategic Enterprise Management
Sap Se Sap Strategic Enterprise Management (balanced Scorecard In Bsp Application)
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-02-10T16:12:07.367Z

Reserved: 2026-01-21T22:15:36.673Z

Link: CVE-2026-24327

cve-icon Vulnrichment

Updated: 2026-02-10T16:12:04.040Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-10T04:16:05.113

Modified: 2026-02-17T15:12:00.680

Link: CVE-2026-24327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T21:00:12Z

Weaknesses