CVE-2026-24327

MEDIUM

SAP Strategic Enterprise Management - Info Disclosure

Title source: llm
STIX 2.1

Description

Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This leads to low impact on confidentiality and no effect on integrity or availability.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3680390

Scores

CVSS v3 4.3
EPSS 0.0001
EPSS Percentile 2.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (12)
sap/strategic_enterprise_management 600
sap/strategic_enterprise_management 602
sap/strategic_enterprise_management 603
sap/strategic_enterprise_management 604
sap/strategic_enterprise_management 605
sap/strategic_enterprise_management 634
sap/strategic_enterprise_management 700
sap/strategic_enterprise_management 736
sap/strategic_enterprise_management 746
sap/strategic_enterprise_management 747
... and 2 more
Published Feb 10, 2026
Tracked Since Feb 18, 2026