3.8
/ 10
LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Description
Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in low impact on confidentiality and integrity, with no impact on application availability.
Basic Information
ID
CVE-2026-0504
Source
sap
Published
Jan 13, 2026 at 01:14
Affected Product
Vendor
SAP_SE
Product
SAP Identity Management
Version
IDM_CLM_REST_API 8.0
Affected Versions
SAP_SE SAP Identity Management IDM_CLM_REST_API 8.0
SAP_SE SAP Identity Management IDMIC 8.0
SAP_SE SAP Identity Management IDMIC 8.0