{"id":"CVE-2026-76968","title":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state…","summary":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-497"],"vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","affected":["sap_web_dispatcher_internet_communication_manager_and_sap_content_server KRNL64NUC 7.22","sap_web_dispatcher_internet_communication_manager_and_sap_content_server 7.22EXT","sap_web_dispatcher_internet_communication_manager_and_sap_content_server KRNL64UC 7.22","sap_web_dispatcher_internet_communication_manager_and_sap_content_server 7.53","sap_web_dispatcher_internet_communication_manager_and_sap_content_server WEBDISP 7.22_EXT","sap_web_dispatcher_internet_communication_manager_and_sap_content_server 7.54","sap_web_dispatcher_internet_communication_manager_and_sap_content_server 7.77","sap_web_dispatcher_internet_communication_manager_and_sap_content_server 7.93","sap_web_dispatcher_internet_communication_manager_and_sap_content_server 9.16","sap_web_dispatcher_internet_communication_manager_and_sap_content_server CONTSERV 7.53","sap_web_dispatcher_internet_communication_manager_and_sap_content_server KERNEL 7.22","sap_web_dispatcher_internet_communication_manager_and_sap_content_server 9.18","sap_web_dispatcher_internet_communication_manager_and_sap_content_server 9.19","sap_web_dispatcher_internet_communication_manager_and_sap_content_server 9.20"],"published":"2026-09-08","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:12:59.557","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76968","references":[{"url":"https://me.sap.com/notes/3750721","label":"cna@sap.com"},{"url":"https://url.sap/sapsecuritypatchday","label":"cna@sap.com"}],"tags":["nvd","cve.org"],"epss":0.00392,"epssPercentile":0.30642,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T10:04:30.481799Z"},"ingestedAt":"2026-09-08T15:33:26.981Z","slug":"CVE-2026-76968","body":"## Overview\n\nSAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}