VDB

CVE-2026-76968

CVE-2026-76968 PUBLISHED CVSS 6.5 MEDIUM

Reported by sap · Published September 8, 2026

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content ServerKRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22
SAP_SESAP Web Dispatcher, Internet Communication Manager and SAP Content ServerKRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22

Timeline

  • Sep 8, 2026 EPSS Score
  • Sep 8, 2026 Coalition ESS Score
  • Sep 8, 2026 CVE Published
  • Sep 8, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›