VDB
CVE-2026-0504
CVE-2026-0504
PUBLISHED
CVSS 3.799999952316284 LOW
Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in low impact on confidentiality and integrity, with no impact on application availability.
EPSS 0.05% · 15.5th percentile
Risk Scores
CVSS 3.1
3.799999952316284
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.05%
15.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP Identity Management | IDM_CLM_REST_API 8.0, IDMIC 8.0, IDM_CLM_REST_API 8.0 |
Timeline
- Jan 13, 2026 EPSS Score
- Jan 13, 2026 CVE Published
- Jan 13, 2026 CVE Updated
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 16, 2026 EPSS Score
- Jan 19, 2026 EPSS Score
- Jan 22, 2026 EPSS Score
- Jan 25, 2026 EPSS Score
- Jan 28, 2026 EPSS Score
- Jan 31, 2026 EPSS Score