SAP SE Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for SAP SE products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

10

In CISA KEV

6

Beyond CISA KEV

4

Sensor Observed

2

Virtual Patch Available

2

SAP SE KEVs Added by Year

Loading...

10 SAP SE KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2020-6286

The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30,...

Confirmed Not in CISA 12 Jun 2026
CVE-2021-21479

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the...

High Not in CISA 27 Jul 2025
CVE-2021-33690

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions...

High Not in CISA 11 Jul 2025
CVE-2020-6207

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a...

Confirmed In CISA 03 Nov 2021
CVE-2020-6287

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an...

Confirmed In CISA 03 Nov 2021
CVE-2018-2380

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus...

Confirmed In CISA 03 Nov 2021
CVE-2021-38163

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative...

Confirmed In CISA 09 Jun 2022
CVE-2022-22536

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are...

Confirmed In CISA 18 Aug 2022
CVE-2019-0344

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to...

Confirmed In CISA 30 Sep 2024
CVE-2020-6308

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary...

High Not in CISA 20 Oct 2020

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
  • CWE-306 — Missing Authentication for Critical Function 2
  • CWE-918 — Server-Side Request Forgery (SSRF) 2
  • CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
  • CWE-502 — Deserialization of Untrusted Data 1
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology