Putting it in context, it is critical enough as to be excluded from SAP_ALL as standard.
Have a look at SAP Note 1416085 - a snippet of which is: "...If you enter the full authorization (*) in one or more of these three fields, you allow the logon from any system, client, or any user, and as a result, you may produce significant security risks..."