CVE-2017-16684: SAP Business Intelligence Promotion Management Application

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionalities that require user identity.

Affected products

  • SAP Business Intelligence Promotion Management Application: version 4.10 only; version 4.20 only; version 4.30 only

Published 2017-12-12. Last modified 2026-06-17.