SAP Knowledge Base Article - Preview

3799371 - SAP Identity Management 8.0 - Apache CXF vulnerability scan findings assessed as false positives

Symptom

  •  A vulnerability assessment (VA) scan of the SAP Identity Management system reports one or more Apache CXF CVEs against the cxf-core library.

    - Affected paths typically include locations such as:

      - /usr/sap/<SID>/J00/j2ee/cluster/apps/sap.com/idmdevstudio/.../WEB-INF/lib/cxf-core-*.jar

      - /usr/sap/<SID>/IDM00/Identity_Center/Java/cxf-core-*.jar

      - /usr/sap/<SID>/VDS01/VDS/lib/cxf-core-*.jar

    - The scanner recommends upgrading to a fixed Apache CXF version and flags the finding as a security risk.

    - CVEs commonly reported in this pattern include (but are not limited to):

      - CVE-2025-48913 (Untrusted JMS configuration leading to RCE)

      - CVE-2026-44417 (Incomplete fix for CVE-2025-48913, JMS RCE)

      - CVE-2026-44618 (XXE via insecure XML parser in WS-Transfer module)

      - CVE-2026-44930 (LDAP injection in XKMS server certificate repository)


Read more...

Environment

  • SAP Identity Management 8.0

Product

SAP Identity Management 8.0

Keywords

apache cxf, cxf-core, identity management 8.0, vulnerability scan, false positive, cve-2026-44417, cve-2026-44618, cve-2026-44930, jms configuration, ws-transfer, xkms, xxe, rce, ldap injection, java 8 , KBA , BC-IAM-IDM , Identity Management , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.