CVE-2026-76968
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.23%
- CWE
- CWE-497
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
- SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
- SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
- SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
- SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
- SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
- SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
- SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Weakness type
Related vulnerabilities
- CVE-2026-81394 — Microsoft Excel Information Disclosure Vulnerability
- CVE-2026-81387 — Microsoft Excel Information Disclosure Vulnerability
- CVE-2026-69315 — Windows License Manager Information Disclosure Vulnerability
- CVE-2026-68842 — Windows MIDI Service Module Information Disclosure Vulnerability
- CVE-2026-71330 — Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
- CVE-2026-69832 — Win32k Information Disclosure Vulnerability
- CVE-2026-69723 — Windows Kernel Information Disclosure Vulnerability
- CVE-2026-69406 — Windows Kernel Information Disclosure Vulnerability