---
id: CVE-2026-76968
title: >-
  SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
  allows an authenticated low-privileged attacker to access certain
  administrative functionality or interface and obtain sensitive information
  about the system state…
summary: >-
  SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
  allows an authenticated low-privileged attacker to access certain
  administrative functionality or interface and obtain sensitive information
  about the system state…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-497
vendor: SAP_SE
product: 'SAP Web Dispatcher, Internet Communication Manager and SAP Content Server'
affected:
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    KRNL64NUC 7.22
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    7.22EXT
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    KRNL64UC 7.22
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    7.53
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    WEBDISP 7.22_EXT
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    7.54
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    7.77
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    7.93
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    9.16
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    CONTSERV 7.53
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    KERNEL 7.22
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    9.18
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    9.19
  - >-
    sap_web_dispatcher_internet_communication_manager_and_sap_content_server
    9.20
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76968'
references:
  - url: 'https://me.sap.com/notes/3750721'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
  - cve.org
epss: 0.00392
epssPercentile: 0.30642
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T10:04:30.481799Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
---

## Overview

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
