Sceawere

Vulnerability Detail

CVE-2026-58235UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SAP NetWeaver ADS Outdated Libraries Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
4h ago
Vendor
SAP_SE
Product
SAP NetWeaver AS Java (Adobe Document Services)
Attack Type
CWE-1395: Dependency on Vulnerable Third-Party Component
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-11T01:17:21.437Z",
  "pubdate": "2026-08-11T01:17:21.437Z",
  "executiveSummary": "SAP NetWeaver Application Server Java (Adobe Document Service) utilizes outdated open-source cryptographic and data transfer libraries containing known vulnerabilities addressed in newer releases. This component-level weakness exposes the underlying architecture to potential security degradation when compromised.\nSuccessful exploitation of these outdated dependencies yields a low overall impact across the security triad, affecting confidentiality, integrity, and availability. The attack vector requires a low-privileged authenticated adversary capable of interacting with the targeted service.\nWhile no specific public exploit payloads are currently documented for this exact context, the presence of unpatched third-party libraries introduces inherent systemic risk. Threat actors with valid low-privileged credentials can potentially leverage these inherited weaknesses to interact with vulnerable functions within the cryptographic and data transfer modules.\nThe risk implications include potential subversion of secure data transfer mechanisms or cryptographic routines managed by the Adobe Document Service. Remediation necessitates updating the affected third-party libraries and underlying software components to the vendor-recommended patched versions.",
  "technicalDetails": "The root cause of this vulnerability stems from the integration of outdated open-source cryptographic and data transfer libraries within the SAP NetWeaver Application Server Java architecture, specifically impacting the Adobe Document Service component. These third-party dependencies contain documented security flaws corresponding to later fixed releases that were not incorporated into the affected product baseline.\nExploitation of the affected component requires an attacker to possess valid low-privileged credentials, granting them authenticated access to the network-exposed SAP NetWeaver Application Server Java interface. The attack flow initiates when the authenticated low-privileged user interacts with the Adobe Document Service, routing malicious or malformed inputs through the vulnerable cryptographic or data transfer routines managed by the outdated open-source libraries.\nBecause the underlying libraries contain known flaws, the targeted functions fail to securely process cryptographic operations or data encapsulation protocols. Depending on the specific library flaws present, a successful attack could manipulate data transfer parameters or disrupt cryptographic service execution.\nPost-exploitation impact remains constrained due to the architectural limitations of the component, resulting in low impact on confidentiality, integrity, and availability. No specific exploit code or automated payload behavior is currently detailed, but the attack methodology relies on leveraging known weaknesses in unpatched third-party software components executing within the Java application server environment."
}
CVE-2026-58235: SAP NetWeaver ADS Outdated Libraries Vulnerability (MEDIUM Severity, CVSS: 6.3) - Sceawere