SAP Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for SAP products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

19

In CISA KEV

14

Beyond CISA KEV

5

Sensor Observed

3

Virtual Patch Available

3

SAP KEVs Added by Year

Loading...

19 SAP KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2020-6286

The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30,...

Confirmed Not in CISA 12 Jun 2026
CVE-2021-21479

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the...

High Not in CISA 27 Jul 2025
CVE-2021-33690

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions...

High Not in CISA 11 Jul 2025
CVE-2025-42999

Insecure Deserialization in SAP NetWeaver (Visual Composer development server)

Confirmed In CISA 01 Jun 2026
CVE-2017-9844

SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized...

High Not in CISA 01 May 2025
CVE-2025-31324

Missing Authorization check in SAP NetWeaver (Visual Composer development server)

Confirmed In CISA 28 Apr 2025
CVE-2016-3976

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot...

Confirmed In CISA 03 Nov 2021
CVE-2020-6207

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a...

Confirmed In CISA 03 Nov 2021
CVE-2020-6287

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an...

Confirmed In CISA 03 Nov 2021
CVE-2016-9563

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the...

Confirmed In CISA 03 Nov 2021
CVE-2010-5326

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote...

Confirmed In CISA 03 Nov 2021
CVE-2018-2380

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus...

Confirmed In CISA 03 Nov 2021
CVE-2016-2388

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP...

Confirmed In CISA 09 Jun 2022
CVE-2016-2386

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via...

Confirmed In CISA 09 Jun 2022
CVE-2021-38163

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative...

Confirmed In CISA 09 Jun 2022
CVE-2022-22536

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are...

Confirmed In CISA 18 Aug 2022
CVE-2019-0344

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to...

Confirmed In CISA 30 Sep 2024
CVE-2017-12637

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote...

Confirmed In CISA 19 Mar 2025
CVE-2020-6308

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary...

High Not in CISA 20 Oct 2020

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
  • CWE-502 — Deserialization of Untrusted Data 3
  • CWE-306 — Missing Authentication for Critical Function 3
  • CWE-918 — Server-Side Request Forgery (SSRF) 2
  • CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1
  • CWE-611 — Improper Restriction of XML External Entity Reference 1
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology