Impact
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server expose sensitive system state data through administrative functionality that can be accessed by an authenticated user with low privileges. The exposure of this information can compromise the confidentiality of the application and potentially aid further exploitation attempts, while leaving integrity and availability unaffected.
Affected Systems
Vendors: SAP. Products: SAP Web Dispatcher, Internet Communication Manager, SAP Content Server. No specific version range is listed, so all deployed instances of the mentioned components are potentially affected.
Risk and Exploitability
The vulnerability scores a moderate CVSS of 6.5 and is not catalogued in CISA’s KEV database, with no EPSS data available. Attackers would need legitimate credentials that grant low‑level access to the system; once logged in, they can use the exposed administrative interface to read sensitive configuration and state information. The lack of impact on integrity and availability limits the immediate damage, but the disclosed data can serve as a foothold for more severe attacks.
OpenCVE Enrichment