CVE-2026-76968

Summary

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content ServerKRNL64NUC 7.22affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content Server7.22EXTaffected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content ServerKRNL64UC 7.22affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content Server7.53affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content ServerWEBDISP 7.22_EXTaffected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content Server7.54affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content Server7.77affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content Server7.93affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content Server9.16affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content ServerCONTSERV 7.53affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content ServerKERNEL 7.22affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content Server9.18affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content Server9.19affected
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content Server9.20affected

Weaknesses

  • CWE-497: CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere

References