Outdated Libraries in SAP NetWeaver Application Server Java Expose Security Risks
CVE-2026-58235

6.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 August 2026

What is CVE-2026-58235?

The SAP NetWeaver Application Server Java, specifically the Adobe Document Service component, utilizes outdated open-source cryptographic and data transfer libraries. These libraries are known to have vulnerabilities that can potentially be exploited by low-privileged authenticated users. Although no specific exploit exists at this time, the weaknesses in these libraries could lead to impacts on the system's confidentiality, integrity, and availability. Organizations using this software should assess their risk and take appropriate remediation steps as necessary.

Affected Version(s)

SAP NetWeaver AS Java (Adobe Document Services) ADSSAP 7.50

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.