CVE-2025-42927 LOW

CVE-2025-42927: Information Disclosure due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Service)

Vendor Sap_Se
Product SAP NetWeaver AS Java (Adobe Document Service)
Weakness CWE-1395
Published September 9, 2025
Last update September 9, 2025

CVSS base score

3.4/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

What the vulnerability does

Description

SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on confidentiality and integrity, with no impact on availability.

Key dates

Disclosure timeline

September 9, 2025 CVE published
September 9, 2025 Record updated