CVE-2026-76968
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | KRNL64NUC 7.22 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 7.22EXT | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | KRNL64UC 7.22 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 7.53 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | WEBDISP 7.22_EXT | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 7.54 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 7.77 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 7.93 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 9.16 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | CONTSERV 7.53 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | KERNEL 7.22 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 9.18 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 9.19 | affected |
| SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 9.20 | affected |
Weaknesses
- CWE-497: CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.