Description
SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system.
Published: 2026-08-11
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from the use of outdated open source cryptographic and data transfer libraries within SAP NetWeaver Application Server Java’s Adobe Document Service. The weakness, classified as CWE‑1395, allows a low‑privileged authenticated attacker to exploit the component, although no specific exploit has been documented. Successful exploitation would lead to a low‑impact compromise of confidentiality, integrity, and availability.

Affected Systems

The affected product is SAP NetWeaver Application Server Java, specifically the Adobe Document Service component. No version range is specified in the available data; therefore the scope includes any installations that have not incorporated the patches referenced by SAP.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is a low‑privileged authenticated user who has legitimate access to the Adobe Document Service. While no proof of exploitation exists, the combination of a moderate CVSS and a potentially authenticated attack path suggests a moderate risk that warrants timely remediation.

Generated by OpenCVE AI on August 11, 2026 at 01:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security update from SAP note 3758318 to replace the outdated cryptographic and data transfer libraries in Adobe Document Service.
  • Ensure the system receives SAP Security Patch Day updates so the latest fixes for the component are applied.
  • If a patch cannot be applied immediately, restrict Adobe Document Service access to trusted administrators or disable the service to reduce the attack surface.

Generated by OpenCVE AI on August 11, 2026 at 01:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Netweaver As Java (adobe Document Services)
Vendors & Products Sap Se
Sap Se sap Netweaver As Java (adobe Document Services)

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system.
Title Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
Weaknesses CWE-1395
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Sap Se Sap Netweaver As Java (adobe Document Services)
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:32:00.620Z

Reserved: 2026-06-29T19:34:28.222Z

Link: CVE-2026-58235

cve-icon Vulnrichment

Updated: 2026-08-11T14:31:56.053Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T01:17:21.437

Modified: 2026-08-26T19:00:14.450

Link: CVE-2026-58235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:21:07Z

Weaknesses
  • CWE-1395

    Dependency on Vulnerable Third-Party Component