VendorsSAPidentity_managementall versions
Vulnerabilities

SAP Identity Management

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-0301
Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing.
Published 2019-05-14 · Modified
8.8EPSS 0.011
CVE-2020-6258
SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certain sensitive information of the victim, leading to Missing Authorization Check.
Published 2020-05-12 · Modified
6.5EPSS 0.007
CVE-2018-2416
SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.
Published 2018-05-09 · Modified
5.5EPSS 0.015
CVE-2018-2417
Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be restricted.
Published 2018-05-09 · Modified
5.3EPSS 0.013