Impact
The vulnerability is a missing authorization check in the Balanced Scorecard component of SAP Strategic Enterprise Management’s Business Server Pages. An authenticated user can view data that they should not have access to, creating a modest breach of confidentiality while leaving integrity and availability unaffected.
Affected Systems
This flaw affects SAP Strategic Enterprise Management as identified by SAP SE, covering versions 600, 602, 603, 604, 605, 634, 700, 736, 746, 747, 748, and 800. The issue resides in the Balanced Scorecard web application delivered via Business Server Pages.
Risk and Exploitability
With a CVSS score of 4.3 the overall severity is considered low. The EPSS score of less than 1% reflects a very low likelihood of actual exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a legitimate user account with access to the application; the attacker can exploit the missing check by using their standard credentials to request privileged data via the web interface.
OpenCVE Enrichment