SAP Web Dispatcher, Internet Communication Manager and SAP Content Server vulnerability

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

Published 7 Sep 2026Updated 7 Sep 20262 sources
CVSS 6.5

What happened

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

Affected versions

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server: KRNL64NUC 7.22; 7.22EXT; KRNL64UC 7.22; 7.53; WEBDISP 7.22_EXT; 7.54; 7.77; 7.93; 9.16; CONTSERV 7.53; KERNEL 7.22; 9.18; 9.19; 9.20 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.