VDB

CVE-2026-0504

CVE-2026-0504 PUBLISHED CVSS 3.799999952316284 LOW

Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in low impact on confidentiality and integrity, with no impact on application availability.

EPSS 0.05% · 15.5th percentile

Risk Scores

CVSS 3.1
3.799999952316284
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.05%
15.5th percentile

Affected Products

VendorProductVersions
SAP_SESAP Identity ManagementIDM_CLM_REST_API 8.0, IDMIC 8.0, IDM_CLM_REST_API 8.0

Timeline

  • Jan 13, 2026 EPSS Score
  • Jan 13, 2026 CVE Published
  • Jan 13, 2026 CVE Updated
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 16, 2026 EPSS Score
  • Jan 19, 2026 EPSS Score
  • Jan 22, 2026 EPSS Score
  • Jan 25, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 31, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›