Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in low impact on confidentiality and integrity, with no impact on application availability.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap identity Management |
|
| Vendors & Products |
Sap
Sap identity Management |
Tue, 13 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in low impact on confidentiality and integrity, with no impact on application availability. | |
| Title | Insufficient Input Handling in JNDI Operations of SAP Identity Management | |
| Weaknesses | CWE-943 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2026-01-13T01:14:27.040Z
Updated: 2026-01-13T01:14:27.040Z
Reserved: 2025-12-09T22:06:44.481Z
Link: CVE-2026-0504
No data.
Status : Awaiting Analysis
Published: 2026-01-13T02:15:53.110
Modified: 2026-01-13T14:03:18.990
Link: CVE-2026-0504
No data.