Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)
Vulnerability Description
Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This vulnerability also enables the attacker to change the default settings and modify value fields, which will mislead risk evaluations and falsely lower assessed risk levels. This results in a low impact on the confidentiality and integrity of the data. There is no impact on the application�s availability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
SAP Strategic Enterprise Management 安全漏洞
Vulnerability Description
SAP Strategic Enterprise Management是德国思爱普(SAP)公司的一个企业战略管理软件。 SAP Strategic Enterprise Management存在安全漏洞,该漏洞源于缺少授权检查,可能导致经过身份验证的攻击者访问未授权信息、更改默认设置和修改值字段,误导风险评估并降低风险等级,对机密性和完整性有低影响。
CVSS Information
N/A
Vulnerability Type
N/A