CVE-2026-40132 PUBLISHED

Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)

Assigner: sap
Reserved: 09.04.2026 Published: 12.05.2026 Updated: 12.05.2026

Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This vulnerability also enables the attacker to change the default settings and modify value fields, which will mislead risk evaluations and falsely lower assessed risk levels. This results in a low impact on the confidentiality and integrity of the data. There is no impact on the application�s availability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor SAP_SE
Product SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)
Versions Default: unaffected
  • Version SEM-BW 605 is affected
  • Version 700 is affected
  • Version 736 is affected
  • Version 746 is affected
  • Version 747 is affected
  • Version 748 is affected
  • Version 749 is affected
  • Version 800 is affected

References

Problem Types