Description
Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This vulnerability also enables the attacker to change the default settings and modify value fields, which will mislead risk evaluations and falsely lower assessed risk levels. This results in a low impact on the confidentiality and integrity of the data. There is no impact on the application�s availability.
Published: 2026-05-12
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from a missing authorization check within the Scorecard Wizard component of SAP Strategic Enterprise Management. An attacker who has authenticated successfully can read data that should not be available to them and alter default settings and value fields, leading to distorted risk assessments and falsely lowered risk levels. The defect results in a low impact on the confidentiality and integrity of the data, with no effect on the availability of the application.

Affected Systems

The affected product is SAP Strategic Enterprise Management, specifically the Balanced Scorecard Wizard module on Business Server Pages. No specific version information is provided, so all installations of this module may be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated attacker who has valid credentials. Because the flaw permits information disclosure and configuration changes, the damage a determined adversary can cause is limited to confidentiality and integrity degradation rather than a full compromise. Given the moderate CVSS score and the lack of exploit probability data, the overall risk is moderate but the potential for misrepresenting risk levels remains a concern for organizations relying on accurate risk evaluations.

Generated by OpenCVE AI on May 12, 2026 at 04:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review SAP SE Note 3721959 for the latest patch and apply it to all systems running the Scorecard Wizard component.
  • Configure role‑based access controls to limit access to the Balanced Scorecard Wizard, and verify that all pages enforce proper authorization checks.
  • Monitor SAP application logs for unauthorized configuration changes and ensure that any alterations to default settings require elevated privileges.

Generated by OpenCVE AI on May 12, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Strategic Enterprise Management (bsp Application Balanced Scorecard Wizard)
Vendors & Products Sap Se
Sap Se sap Strategic Enterprise Management (bsp Application Balanced Scorecard Wizard)

Tue, 12 May 2026 03:00:00 +0000

Type Values Removed Values Added
Description Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This vulnerability also enables the attacker to change the default settings and modify value fields, which will mislead risk evaluations and falsely lower assessed risk levels. This results in a low impact on the confidentiality and integrity of the data. There is no impact on the application�s availability.
Title Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Sap Se Sap Strategic Enterprise Management (bsp Application Balanced Scorecard Wizard)
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-05-12T02:21:06.768Z

Reserved: 2026-04-09T17:29:44.663Z

Link: CVE-2026-40132

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-12T03:16:12.043

Modified: 2026-05-12T03:16:12.043

Link: CVE-2026-40132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T09:22:00Z

Weaknesses