6.5

CVE-2026-76968

Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Default Statusunaffected
Version KRNL64NUC 7.22
Status affected
Version 7.22EXT
Status affected
Version KRNL64UC 7.22
Status affected
Version 7.53
Status affected
Version WEBDISP 7.22_EXT
Status affected
Version 7.54
Status affected
Version 7.77
Status affected
Version 7.93
Status affected
Version 9.16
Status affected
Version CONTSERV 7.53
Status affected
Version KERNEL 7.22
Status affected
Version 9.18
Status affected
Version 9.19
Status affected
Version 9.20
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.139
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
SAP 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3750721