Authenticated Information Disclosure in SAP Web Dispatcher, ICM and Content Server
AI analysis
CVE-2026-76968 is an information disclosure flaw (CWE-497) in SAP Web Dispatcher, SAP Internet Communication Manager (ICM), and SAP Content Server in which an authenticated user with only low privileges can reach administrative functionality or interfaces that should be off-limits to them. The attacker triggers the flaw by sending requests over the network to these administrative endpoints using valid low-privileged credentials, requiring no user interaction. By reading the exposed administrative interface, the attacker obtains sensitive information about the system state, which could be used to facilitate further attacks, although integrity and availability are not affected. Any organization running the affected SAP components is exposed, and because ICM is embedded in SAP's application server stack, this potentially touches a very broad base of SAP on-premise and cloud deployments. As of now there is no evidence of exploitation, no public proof-of-concept, and the issue is not in CISA's KEV catalog; fixes were shipped with the SAP September 2026 Security Patch Day updates.
What to do: Apply the SAP security fixes released with the September 2026 Security Patch Day (check SAP Note/CVE-2026-76968 for the exact patch levels for Web Dispatcher, ICM and Content Server, as version details are not in this data). Until patching, restrict access to the administrative interfaces of these components using network controls and review which low-privileged users can reach them. Since exploitation requires valid credentials, prioritize review of recently created or over-privileged service and end-user accounts.
Affected
| SAP Web Dispatcher | — |
| SAP Internet Communication Manager (ICM) | — |
| SAP Content Server | — |
Estimated exposure
large≈tens of thousands of SAP installations worldwide (ICM is bundled with essentially every SAP NetWeaver-based system) — ICM ships inside every SAP NetWeaver Application Server and Web Dispatcher is a standard component of SAP HTTP infrastructures, so global deployment likely exceeds 100,000 systems, but the requirement for a valid low-privileged account and…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.