Symptom
-
A vulnerability assessment (VA) scan of the SAP Identity Management system reports one or more Apache CXF CVEs against the cxf-core library.
- Affected paths typically include locations such as:
- /usr/sap/<SID>/J00/j2ee/cluster/apps/sap.com/idmdevstudio/.../WEB-INF/lib/cxf-core-*.jar
- /usr/sap/<SID>/IDM00/Identity_Center/Java/cxf-core-*.jar
- /usr/sap/<SID>/VDS01/VDS/lib/cxf-core-*.jar
- The scanner recommends upgrading to a fixed Apache CXF version and flags the finding as a security risk.
- CVEs commonly reported in this pattern include (but are not limited to):
- CVE-2025-48913 (Untrusted JMS configuration leading to RCE)
- CVE-2026-44417 (Incomplete fix for CVE-2025-48913, JMS RCE)
- CVE-2026-44618 (XXE via insecure XML parser in WS-Transfer module)
- CVE-2026-44930 (LDAP injection in XKMS server certificate repository)
Read more...
Environment
- SAP Identity Management 8.0
Product
Keywords
apache cxf, cxf-core, identity management 8.0, vulnerability scan, false positive, cve-2026-44417, cve-2026-44618, cve-2026-44930, jms configuration, ws-transfer, xkms, xxe, rce, ldap injection, java 8 , KBA , BC-IAM-IDM , Identity Management , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview