CVE 3.8 LOW

Insufficient Input Handling in JNDI Operations of SAP Identity Management_CVE-2026-0504

3.8 / 10
LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Description

Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in low impact on confidentiality and integrity, with no impact on application availability.

Basic Information

ID CVE-2026-0504
Source sap
Published Jan 13, 2026 at 01:14

Affected Product

Vendor SAP_SE
Product SAP Identity Management
Version IDM_CLM_REST_API 8.0
Affected Versions SAP_SE SAP Identity Management IDM_CLM_REST_API 8.0
SAP_SE SAP Identity Management IDMIC 8.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.