4.3
CVE-2026-24327
- EPSS 0.01%
- Veröffentlicht 10.02.2026 03:04:46
- Zuletzt bearbeitet 17.02.2026 15:12:00
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This leads to low impact on confidentiality and no effect on integrity or availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Strategic Enterprise Management Version600
SAP ≫ Strategic Enterprise Management Version602
SAP ≫ Strategic Enterprise Management Version603
SAP ≫ Strategic Enterprise Management Version604
SAP ≫ Strategic Enterprise Management Version605
SAP ≫ Strategic Enterprise Management Version634
SAP ≫ Strategic Enterprise Management Version700
SAP ≫ Strategic Enterprise Management Version736
SAP ≫ Strategic Enterprise Management Version746
SAP ≫ Strategic Enterprise Management Version747
SAP ≫ Strategic Enterprise Management Version748
SAP ≫ Strategic Enterprise Management Version800
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.014 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@sap.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.