Executive brief
SAP Web Dispatcher, Internet Communication Manager, and SAP Content Server allow authenticated attackers with low privileges to access administrative functions and view sensitive system information. An attacker with a standard user account can bypass access controls to retrieve confidential system state details that could enable further attacks on the SAP environment.
Technical details
This is an information disclosure vulnerability affecting SAP's web communication components. An authenticated attacker with low-privilege credentials can access administrative functionality and retrieve sensitive system state information through improper access controls. The vulnerability requires prior authentication but does not require elevated privileges. The disclosed information could facilitate reconnaissance for subsequent attacks, though the vulnerability itself does not enable code execution, data modification, or service disruption. A patch is available via SAP Security Note 3750721 published on 2026-09-08 as part of SAP's regular Security Patch Day.
Affected products
- SAP Web Dispatcher
- SAP Internet Communication Manager
- SAP Content Server
Timeline
- 2026-09-08: disclosed: Published as part of SAP Security Patch Day
- 2026-09-08: patched: SAP Security Note 3750721 available