CVE-2026-24327

Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This leads to low impact on confidentiality and no effect on integrity or availability.
References
Link Resource
https://me.sap.com/notes/3680390 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:strategic_enterprise_management:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:602:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:603:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:604:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:605:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:634:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:736:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:746:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:748:*:*:*:*:*:*:*
cpe:2.3:a:sap:strategic_enterprise_management:800:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-10 04:16

Updated : 2026-02-17 15:12


NVD link : CVE-2026-24327

Mitre link : CVE-2026-24327

CVE.ORG link : CVE-2026-24327


JSON object : View

Products Affected

sap

  • strategic_enterprise_management
CWE
CWE-862

Missing Authorization