CVE-2025-42927
Description
SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on confidentiality and integrity, with no impact on availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2025-42927 describes a low severity vulnerability in SAP NetWeaver AS Java using an outdated OpenSSL in Adobe Document Service, exploitable only by high-privilege users.
The vulnerability resides in SAP NetWeaver AS Java's Adobe Document Service, which is shipped with an outdated version of the OpenSSL library. The root cause is the failure to update or replace the bundled OpenSSL, leaving known weaknesses present in that library version exploitable within the context of the service.
Exploitation requires the attacker to already possess high system privileges (e.g., administrative access). No network-level or user-interaction precondition is described beyond that privilege requirement. The attack surface is therefore limited to users who already have elevated rights on the affected system.
Successful exploitation could allow an attacker with those high privileges to read or modify system information that the Adobe Document Service processes through the outdated OpenSSL. The impact is rated low for both confidentiality and integrity, and there is no impact on availability.
SAP has not yet released a dedicated security note for this specific CVE as of the publication date, but the vendor's standard patch day process applies. Users should monitor SAP Security Notes and apply any relevant updates for the Adobe Document Service and the bundled OpenSSL library as they become available. Because the CVSS score is low, the fix may be delivered in the next support package rather than an out-of-band patch.
[1]
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.