SAP NetWeaver AS Java Vulnerable Third-Party Component (3758318)

medium Nessus Plugin ID 335408

Synopsis

The remote SAP NetWeaver AS Java server is affected by a vulnerability in a bundled third-party component.

Description

The version of SAP NetWeaver Application Server Java detected on the remote host is affected by the use of a vulnerable third-party component as referenced in SAP Security Note 3758318:

- SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confidentiality, integrity, and availability of the system. (CVE-2026-58235)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Apply the appropriate patch according to the vendor advisory.

See Also

https://me.sap.com/notes/3758318

http://www.nessus.org/u?0b3f7da5

Plugin Details

Severity: Medium

ID: 335408

File Name: sap_netweaver_as_java_3758318.nasl

Version: 1.1

Type: Remote

Family: Web Servers

Published: 8/14/2026

Updated: 8/14/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.41

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2026-58235

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Vulnerability Information

CPE: cpe:/a:sap:netweaver_application_server

Required KB Items: Settings/ParanoidReport, installed_sw/SAP Netweaver Application Server (AS)

Patch Publication Date: 8/11/2026

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-58235

IAVA: 2026-A-0825