CVE-2017-16684

EUVD-2017-7868
SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionalities that require user identity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
sapbusiness_intelligence_promotion_management_application
4.10
sapbusiness_intelligence_promotion_management_application
4.20
sapbusiness_intelligence_promotion_management_application
4.30
𝑥
= Vulnerable software versions