SAP Identity Management REST Interface JNDI Injection Vulnerability

Vulnerability

A vulnerability exists in the SAP Identity Management REST interface, allowing authenticated administrators to send malicious REST requests that are improperly sanitized. These requests can be processed by JNDI operations, potentially leading to unauthorized disclosure or modification of data. The vulnerability arises from inadequate input handling and, while it poses a low risk to confidentiality and integrity, it does not affect application availability.

Impact

Exploitation of this vulnerability could result in unauthorized disclosure or modification of data.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, specifically on SAP Security Patch Days, which occur on the second Tuesday of each month.

Added: Jan 13, 2026, 2:24 AM
Updated: Jan 13, 2026, 2:24 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.3
exploitability
4.4
remediation
8.3
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.