Impact
This vulnerability arises from the use of outdated open source cryptographic and data transfer libraries within SAP NetWeaver Application Server Java’s Adobe Document Service. The weakness, classified as CWE‑1395, allows a low‑privileged authenticated attacker to exploit the component, although no specific exploit has been documented. Successful exploitation would lead to a low‑impact compromise of confidentiality, integrity, and availability.
Affected Systems
The affected product is SAP NetWeaver Application Server Java, specifically the Adobe Document Service component. No version range is specified in the available data; therefore the scope includes any installations that have not incorporated the patches referenced by SAP.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is a low‑privileged authenticated user who has legitimate access to the Adobe Document Service. While no proof of exploitation exists, the combination of a moderate CVSS and a potentially authenticated attack path suggests a moderate risk that warrants timely remediation.
OpenCVE Enrichment