me.sap.com
https://me.sap.com/notes/3758318 CVE-2026-58235
MEDIUM
Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
Record summary
CVE-2026-58235 has a selected CVSS score of 6.3 (medium).
Description
SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SAP NetWeaver AS Java (Adobe Document Services)Browse SAP_SE / SAP NetWeaver AS Java (Adobe Document Services)Default status: unaffected | CVE List | ADSSAP 7.50 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-58235 url.sap
https://url.sap/sapsecuritypatchday