Sceawere

Vulnerability Detail

CVE-2026-76968UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SAP Administrative Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
SAP_SE
Product
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Attack Type
CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-08T01:17:55.283Z",
  "pubdate": "2026-09-08T01:17:55.283Z",
  "executiveSummary": "This vulnerability is an information disclosure flaw affecting SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server. The vulnerability allows an authenticated low-privileged user to access sensitive administrative interfaces or functions that should otherwise be restricted.\nThe primary risk is the exposure of internal system state data, configuration details, or operational telemetry which can be leveraged as a reconnaissance vector for further exploitation. Because the vulnerability is confined to information disclosure, it results in a high impact on the confidentiality of the application, while system integrity and availability remain unaffected.\nSuccessful exploitation requires the attacker to possess authenticated access to the target system. Once authenticated, the attacker can interact with administrative endpoints to bypass authorization controls, potentially revealing architecture-specific information that facilitates privilege escalation or targeted attacks against underlying SAP infrastructure components.\nOrganizations using these components should prioritize restricting access to administrative interfaces and monitoring for unauthorized attempts to access management-level endpoints by non-privileged accounts.",
  "technicalDetails": "The vulnerability originates from an authorization bypass mechanism within the administrative interface layers of SAP Web Dispatcher, Internet Communication Manager, and SAP Content Server. While the components are designed to restrict administrative commands and state inspection to high-privileged administrative accounts, the existing access control implementation fails to adequately validate the privileges of an already authenticated low-privileged user during requests to specific diagnostic or management endpoints.\nThe attack flow begins with an authenticated low-privileged user performing reconnaissance to identify reachable administrative interfaces within the SAP environment. Upon locating these sensitive endpoints, the attacker constructs HTTP requests—typically involving specific parameters or header manipulations—that trigger the exposure of system state information. Because the application logic relies on incomplete authorization checks, the server processes these requests and returns sensitive telemetry, environment variables, or internal system configuration metrics directly to the attacker.\nThe vulnerable components involved include the management ports and interfaces managed by the Internet Communication Manager and the Web Dispatcher, as well as the administrative service layer of the SAP Content Server. The disclosure of this information effectively leaks architectural metadata, which serves as a critical reconnaissance step. An attacker can use this data to identify backend server structures, network configurations, or specific software version details, which are then used to tailor subsequent exploit payloads intended for more severe vulnerabilities in the SAP stack.\nThe root cause lies in the inconsistent enforcement of Mandatory Access Control (MAC) or Role-Based Access Control (RBAC) across different segments of the administrative URI path. The application fails to perform a secondary, robust authorization check at the functional level, assuming that network-level access or basic authentication implies a sufficiently high privilege level. Exploitation does not require special interaction with external services, as the communication occurs over established protocol channels (HTTP/HTTPS) between the client and the SAP component.\nPost-exploitation impact is characterized by the harvesting of internal system data. While no direct modification (integrity) or disruption (availability) occurs via this specific vulnerability, the disclosed information provides the tactical intelligence required to circumvent other security controls, thereby increasing the overall attack surface and the probability of a successful multi-stage exploitation campaign."
}
CVE-2026-76968: SAP Administrative Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere