TROYANOSYVIRUS
Voltar para CVEs

CVE-2026-0504

LOW
3.8

Descricao

Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in low impact on confidentiality and integrity, with no impact on application availability.

Detalhes CVE

Pontuacao CVSS v3.13.8
SeveridadeLOW
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosHIGH
Interacao do usuarioNONE
Publicado1/13/2026
Ultima modificacao1/13/2026
Fontenvd
Avistamentos honeypot0

Fraquezas (CWE)

CWE-943

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.