CVE-2026-58235
Received Received - Intake

Outdated Libraries in SAP NetWeaver Application Server Java

Vulnerability report for CVE-2026-58235, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: SAP SE

Description

SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap netweaver_application_server_java *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries with known vulnerabilities. A low-privileged authenticated attacker could exploit these weaknesses to potentially impact confidentiality, integrity, and availability of the system, though no specific exploit is currently known.

Detection Guidance

Detection requires checking for outdated cryptographic and data transfer libraries in SAP NetWeaver Application Server Java. Review installed library versions against known vulnerable releases. Use SAP tools like SAP Note Analyzer or manually inspect library directories for outdated components.

Impact Analysis

This vulnerability could allow a low-privileged authenticated attacker to affect the confidentiality, integrity, and availability of the SAP NetWeaver system. The impact is described as low, but successful exploitation may still disrupt services or expose sensitive data.

Compliance Impact

The vulnerability involves outdated cryptographic and data transfer libraries in SAP NetWeaver Application Server Java, which could lead to low impact on confidentiality, integrity, and availability. This may affect compliance with standards like GDPR and HIPAA by potentially exposing sensitive data due to weak cryptographic protections or data transfer issues.

Mitigation Strategies

Update SAP NetWeaver Application Server Java to the latest version to replace outdated cryptographic and data transfer libraries. Apply patches from SAP as soon as they are available. Monitor SAP security notes for updates related to this component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58235. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart