SAP Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for SAP products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
19
In CISA KEV
14
Beyond CISA KEV
5
Sensor Observed
3
Virtual Patch Available
3
SAP KEVs Added by Year
19 SAP KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2020-6286
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30,... |
SAP NetWeaver AS JAVA (LM Configuration Wizard) | Confirmed | Not in CISA | 12 Jun 2026 |
|
CVE-2021-21479
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the... |
SCIMono | High | Not in CISA | 27 Jul 2025 |
|
CVE-2021-33690
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions... |
SAP NetWeaver Development Infrastructure (Component Build Service) | High | Not in CISA | 11 Jul 2025 |
|
CVE-2025-42999
Insecure Deserialization in SAP NetWeaver (Visual Composer development server) |
SAP NetWeaver (Visual Composer development server) | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2017-9844
SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized... |
NetWeaver | High | Not in CISA | 01 May 2025 |
|
CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server) |
SAP NetWeaver (Visual Composer development server) | Confirmed | In CISA | 28 Apr 2025 |
|
CVE-2016-3976
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot... |
NetWeaver AS Java | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-6207
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a... |
SAP Solution Manager (User Experience Monitoring) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-6287
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an... |
SAP NetWeaver AS JAVA (LM Configuration Wizard) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2016-9563
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the... |
NetWeaver AS JAVA | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2010-5326
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote... |
NetWeaver Application Server Java | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-2380
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus... |
SAP CRM | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2016-2388
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP... |
NetWeaver AS JAVA | Confirmed | In CISA | 09 Jun 2022 |
|
CVE-2016-2386
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via... |
NetWeaver J2EE Engine | Confirmed | In CISA | 09 Jun 2022 |
|
CVE-2021-38163
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative... |
SAP NetWeaver (Visual Composer 7.0 RT) | Confirmed | In CISA | 09 Jun 2022 |
|
CVE-2022-22536
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are... |
SAP NetWeaver and ABAP Platform, SAP Web Dispatcher, SAP Content Server | Confirmed | In CISA | 18 Aug 2022 |
|
CVE-2019-0344
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to... |
SAP Commerce Cloud (virtualjdbc extension) | Confirmed | In CISA | 30 Sep 2024 |
|
CVE-2017-12637
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote... |
NetWeaver Application Server Java | Confirmed | In CISA | 19 Mar 2025 |
|
CVE-2020-6308
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary... |
SAP BusinessObjects Business Intelligence Platform (Web Services) | High | Not in CISA | 20 Oct 2020 |
Common Vulnerability Classes (CWE)
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
- CWE-502 — Deserialization of Untrusted Data 3
- CWE-306 — Missing Authentication for Critical Function 3
- CWE-918 — Server-Side Request Forgery (SSRF) 2
- CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
- CWE-434 — Unrestricted Upload of File with Dangerous Type 1
- CWE-611 — Improper Restriction of XML External Entity Reference 1
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology