medium2026-09-08SAP Web Dispatcher / ICM / Content ServerCVE-2026-76968
Information Disclosure via Administrative Interface
SAP Web Dispatcher / ICM / Content Server
Our Take
One note covering three components suggests a shared configuration or handler flaw. Admin interface exposure on Web Dispatcher and ICM is a reconnaissance gift to an attacker — system topology, routing tables, and connection pool state all become visible. Patch alongside the CVSS 10.0 Kernel note since you're already touching these components.
Vulnerability Detail
Low-privileged user can access administrative functionality and system state information across three components: Web Dispatcher, Internet Communication Manager, and Content Server.
Patch Action
Apply the patch per SAP Note 3750721 for the affected components. Verify affected versions in the official SAP Note.
Patch Info