CVE-2026-76968 PUBLISHED

Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server

Assigner: sap
Reserved: 20.08.2026 Published: 08.09.2026 Updated: 08.09.2026

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor SAP_SE
Product SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Versions Default: unaffected
  • Version KRNL64NUC 7.22 is affected
  • Version 7.22EXT is affected
  • Version KRNL64UC 7.22 is affected
  • Version 7.53 is affected
  • Version WEBDISP 7.22_EXT is affected
  • Version 7.54 is affected
  • Version 7.77 is affected
  • Version 7.93 is affected
  • Version 9.16 is affected
  • Version CONTSERV 7.53 is affected
  • Version KERNEL 7.22 is affected
  • Version 9.18 is affected
  • Version 9.19 is affected
  • Version 9.20 is affected

References

Problem Types