Onapsis Security Advisory 2026-0045: SAP ADS – XFA injection in wsalvpdf

August 5, 2026

Onapsis Security Advisory 2026-0045: SAP ADS – XFA injection in wsalvpdf


Impact on Business

An unauthenticated attacker can inject malicious code into the SAP Adobe Document Services (ADS) component. This can lead to the disclosure of sensitive system information and cause a denial of service (DoS) condition, rendering the PDF generation service unavailable and disrupting business processes that rely on document rendering.


Vulnerability Details

A SOAP web service in SAP Adobe Document Services (ADS) allows an unauthenticated attacker to inject arbitrary XFA (XML Forms Architecture) code during PDF generation requests. By crafting specific requests, an attacker can execute scripts that retrieve internal system information or exhaust the available XMLForm services. Exhausting these services prevents the system from processing legitimate PDF rendering requests, resulting in a denial of service condition for the ADS component.


Solution

SAP has released SAP Note 3485284 which provides patched versions of the affected components.

The patches can be downloaded from https://me.sap.com/notes/3485284.

Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.


Report Timeline

  • 05/02/2024: Onapsis reports vulnerability to SAP
  • 08/13/2024: SAP issues the patch

References


Advisory Information

  • Public Release Date: 08/05/2026
  • Security Advisory ID: ONAPSIS-2026-0045
  • Researcher(s): Fabian Hagg, Yvan Genuer

Vulnerability Information

  • Vendor: SAP
  • Affected Components: SAP NetWeaver JAVA, SAP Adobe Document Services (ADS) (Check SAP Note 3485284 for detailed information on affected releases)
  • Vulnerability Class: CWE-94: Improper Control of Generation of Code
  • CVSS v3 score: 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
  • Risk Level: High
  • Assigned CVE: CVE-2024-42374
  • Vendor patch Information: SAP Security NOTE 3485284

Affected Components Description

  • SAP NetWeaver JAVA 7.50
  • SAP Adobe Document Service 7.50

About our Research Labs

Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.

Find all reported vulnerabilities at: https://github.com/Onapsis/vulnerability_advisories

This advisory is licensed under a Creative Commons 4.0 BY-ND International License