medium2026-09-08SAP Web Dispatcher / ICM / Content ServerCVE-2026-76968

Information Disclosure via Administrative Interface

SAP Web Dispatcher / ICM / Content Server

Our Take

One note covering three components suggests a shared configuration or handler flaw. Admin interface exposure on Web Dispatcher and ICM is a reconnaissance gift to an attacker — system topology, routing tables, and connection pool state all become visible. Patch alongside the CVSS 10.0 Kernel note since you're already touching these components.

Vulnerability Detail

Low-privileged user can access administrative functionality and system state information across three components: Web Dispatcher, Internet Communication Manager, and Content Server.

Patch Action

Apply the patch per SAP Note 3750721 for the affected components. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

6.5

SAP Note

3750721

CVE

CVE-2026-76968

Published

2026-09-08

← All patches