CVE-2026-58235 PUBLISHED

Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)

Assigner: sap
Reserved: 29.06.2026 Published: 11.08.2026 Updated: 11.08.2026

SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 6.3

Product Status

Vendor SAP_SE
Product SAP NetWeaver AS Java (Adobe Document Services)
Versions Default: unaffected
  • Version ADSSAP 7.50 is affected

References

Problem Types