SAP Web Dispatcher and ICM Internal Testing Interface Exposure Vulnerability

Vulnerability

A vulnerability exists in SAP Web Dispatcher and Internet Communication Manager (ICM) that may expose internal testing interfaces not intended for production use. If these interfaces are enabled, unauthenticated attackers could exploit them to access diagnostic information, send crafted requests, or disrupt services. This vulnerability significantly impacts confidentiality and availability, while having a low impact on the application's integrity.

Impact

Exploitation of this vulnerability could lead to unauthorized access to diagnostic information, disruption of services, or interference with normal application operations.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, where users can find the complete list of security updates and patches. It is recommended to implement these corrections as a priority.

Added: Dec 9, 2025, 7:26 PM
Updated: Dec 9, 2025, 7:26 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
3.8
exploitability
7.6
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.