Advisory
A note with CVSS 3.8 for component BC-IAM-IDM was released by SAP on 13.01.2026. The correction/advisory 3657998 was described with "[CVE-2026-0504] Insufficient Input Handling in JNDI Operations of SAP Identity Management" and affects the system type IDM.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is information disclosure within IDM.
Information disclosure is when an application fails to properly protect sensitive and confidential information from
parties that are not supposed to have access to the subject matter in normal circumstances.
Carefully review every information disclosure vulnerablity in regards to disclosure obligations post-GDPR for
‘Personal data’ under the Data Protection Act 2018.
Risk specification
SAP IDM allows an authenticated attacker to send specially crafted REST requests, which could result in information disclosure and modification due to insufficient input handling.
Solution
The issue has been addressed by properly validating values before they are processed in the application.
The advisory is valid for
- IDMIC 8.0
- IDM_CLM_REST_API 8.0
