{"api_version":"1","generated_at":"2026-09-08T09:14:10+00:00","cve":"CVE-2026-76968","urls":{"html":"https://cve.report/CVE-2026-76968","api":"https://cve.report/api/cve/CVE-2026-76968.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-76968","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-76968"},"summary":{"title":"Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","description":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.","state":"PUBLISHED","assigner":"sap","published_at":"2026-09-08 01:17:55","updated_at":"2026-09-08 01:17:55"},"problem_types":["CWE-497","CWE-497 CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere"],"metrics":[{"version":"3.1","source":"cna@sap.com","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://url.sap/sapsecuritypatchday","name":"https://url.sap/sapsecuritypatchday","refsource":"cna@sap.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://me.sap.com/notes/3750721","name":"https://me.sap.com/notes/3750721","refsource":"cna@sap.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76968","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76968","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected KRNL64NUC 7.22","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected 7.22EXT","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected KRNL64UC 7.22","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected 7.53","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected WEBDISP 7.22_EXT","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected 7.54","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected 7.77","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected 7.93","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected 9.16","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected CONTSERV 7.53","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected KERNEL 7.22","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected 9.18","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected 9.19","platforms":[]},{"source":"CNA","vendor":"SAP_SE","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","version":"affected 9.20","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","vendor":"SAP_SE","versions":[{"status":"affected","version":"KRNL64NUC 7.22"},{"status":"affected","version":"7.22EXT"},{"status":"affected","version":"KRNL64UC 7.22"},{"status":"affected","version":"7.53"},{"status":"affected","version":"WEBDISP 7.22_EXT"},{"status":"affected","version":"7.54"},{"status":"affected","version":"7.77"},{"status":"affected","version":"7.93"},{"status":"affected","version":"9.16"},{"status":"affected","version":"CONTSERV 7.53"},{"status":"affected","version":"KERNEL 7.22"},{"status":"affected","version":"9.18"},{"status":"affected","version":"9.19"},{"status":"affected","version":"9.20"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.</p>"}],"value":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-497","description":"CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere","lang":"eng","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T00:12:42.912Z","orgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","shortName":"sap"},"references":[{"url":"https://me.sap.com/notes/3750721"},{"url":"https://url.sap/sapsecuritypatchday"}],"source":{"discovery":"UNKNOWN"},"title":"Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server","x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","assignerShortName":"sap","cveId":"CVE-2026-76968","datePublished":"2026-09-08T00:12:42.912Z","dateReserved":"2026-08-20T05:33:36.764Z","dateUpdated":"2026-09-08T00:12:42.912Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 01:17:55","lastModifiedDate":"2026-09-08 01:17:55","problem_types":["CWE-497","CWE-497 CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere"],"metrics":{"cvssMetricV31":[{"source":"cna@sap.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"76968","Ordinal":"1","Title":"Information Disclosure vulnerability in SAP Web Dispatcher, Inte","CVE":"CVE-2026-76968","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"76968","Ordinal":"1","NoteData":"SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.","Type":"Description","Title":"Information Disclosure vulnerability in SAP Web Dispatcher, Inte"}]}}}