CVE-2026-0504: Insufficient Input Handling in JNDI Operations of SAP Identity Management
Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in low impact on confidentiality and integrity, with no impact on application availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0504?
CVE-2026-0504 is classified with a high severity due to the potential for executing unauthorized commands through manipulated input.
How do I fix CVE-2026-0504?
To fix CVE-2026-0504, ensure that you update your SAP Identity Management to the latest patched version provided by SAP.
Who is affected by CVE-2026-0504?
Any organization using SAP Identity Management is at risk if they have administrator access configured for REST interface operations.
What types of attacks can CVE-2026-0504 enable?
CVE-2026-0504 can allow attackers to exploit JNDI operations to perform remote code execution via specially crafted REST requests.
Is CVE-2026-0504 exploitable without authentication?
No, exploitation of CVE-2026-0504 requires an authenticated administrator to submit malicious requests.