CVE 5.4 MEDIUM

Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)_CVE-2026-40132

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This vulnerability also enables the attacker to change the default settings and modify value fields, which will mislead risk evaluations and falsely lower assessed risk levels. This results in a low impact on the confidentiality and integrity of the data. There is no impact on the application�s availability.

Basic Information

ID CVE-2026-40132
Source sap
Published May 12, 2026 at 02:21

Affected Product

Vendor SAP_SE
Product SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)
Version SEM-BW 605
Affected Versions SAP_SE SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) SEM-BW 605
SAP_SE SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) 700
SAP_SE SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) 736
SAP_SE SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) 746
SAP_SE SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) 747
SAP_SE SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) 748
SAP_SE SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) 749
SAP_SE SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) 800

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.