Description
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server expose sensitive system state data through administrative functionality that can be accessed by an authenticated user with low privileges. The exposure of this information can compromise the confidentiality of the application and potentially aid further exploitation attempts, while leaving integrity and availability unaffected.

Affected Systems

Vendors: SAP. Products: SAP Web Dispatcher, Internet Communication Manager, SAP Content Server. No specific version range is listed, so all deployed instances of the mentioned components are potentially affected.

Risk and Exploitability

The vulnerability scores a moderate CVSS of 6.5 and is not catalogued in CISA’s KEV database, with no EPSS data available. Attackers would need legitimate credentials that grant low‑level access to the system; once logged in, they can use the exposed administrative interface to read sensitive configuration and state information. The lack of impact on integrity and availability limits the immediate damage, but the disclosed data can serve as a foothold for more severe attacks.

Generated by OpenCVE AI on September 8, 2026 at 01:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update for SAP Web Dispatcher, Internet Communication Manager, and SAP Content Server.
  • Restrict access to the administrative interface for these components to a trusted network or IP range.
  • Ensure that user accounts possess the minimum privileges required; remove or disable unused high‑privilege accounts.
  • Monitor authentication logs for unexpected or repeated access attempts to the administrative console.

Generated by OpenCVE AI on September 8, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.
Title Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-09-08T00:12:42.912Z

Reserved: 2026-08-20T05:33:36.764Z

Link: CVE-2026-76968

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T01:17:55.283

Modified: 2026-09-08T01:17:55.283

Link: CVE-2026-76968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T02:00:20Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere