SAP vendor intelligence

SAP Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting SAP products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse SAP KEVs Full KEV feed
Total KEVs
20
Known exploited vulnerabilities affecting SAP products
In CISA KEV
14
Records also listed in the official catalog
Beyond CISA KEV
6
Additional exploited CVEs absent from CISA KEV
Sensor Observed
5
SAP KEVs with sensor-observed exploitation activity

The catalog gap matters for SAP exposure

Six of the twenty exploited SAP CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 30% of this vendor portfolio.

70%
Covered by CISA
30%
Beyond CISA
16
Product families

Attested SAP CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-58231

Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

SAP Commerce Cloud (Data Hub Adapter) Confirmed Beyond CISA 14 Aug 2026
CVE-2020-6286

The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30,...

SAP NetWeaver AS JAVA (LM Configuration Wizard) Confirmed Beyond CISA 12 Jun 2026
CVE-2021-21479

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the...

SCIMono High Beyond CISA 27 Jul 2025
CVE-2021-33690

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions...

SAP NetWeaver Development Infrastructure (Component Build Service) High Beyond CISA 11 Jul 2025
CVE-2025-42999

Insecure Deserialization in SAP NetWeaver (Visual Composer development server)

SAP NetWeaver (Visual Composer development server) Confirmed In CISA 01 Jun 2026
CVE-2017-9844

SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized...

NetWeaver High Beyond CISA 01 May 2025
CVE-2025-31324

Missing Authorization check in SAP NetWeaver (Visual Composer development server)

SAP NetWeaver (Visual Composer development server) Confirmed In CISA 28 Apr 2025
CVE-2016-3976

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot...

NetWeaver AS Java Confirmed In CISA 03 Nov 2021
CVE-2020-6207

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a...

SAP Solution Manager (User Experience Monitoring) Confirmed In CISA 03 Nov 2021
CVE-2020-6287

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an...

SAP NetWeaver AS JAVA (LM Configuration Wizard) Confirmed In CISA 03 Nov 2021
CVE-2016-9563

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the...

NetWeaver AS JAVA Confirmed In CISA 03 Nov 2021
CVE-2010-5326

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote...

NetWeaver Application Server Java Confirmed In CISA 03 Nov 2021
CVE-2018-2380

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus...

SAP CRM Confirmed In CISA 03 Nov 2021
CVE-2016-2388

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP...

NetWeaver AS JAVA Confirmed In CISA 09 Jun 2022
CVE-2016-2386

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via...

NetWeaver J2EE Engine Confirmed In CISA 09 Jun 2022
CVE-2021-38163

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative...

SAP NetWeaver (Visual Composer 7.0 RT) Confirmed In CISA 09 Jun 2022
CVE-2022-22536

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are...

SAP NetWeaver and ABAP Platform, SAP Web Dispatcher, SAP Content Server Confirmed In CISA 18 Aug 2022
CVE-2019-0344

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to...

SAP Commerce Cloud (virtualjdbc extension) Confirmed In CISA 30 Sep 2024
CVE-2017-12637

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote...

NetWeaver Application Server Java Confirmed In CISA 19 Mar 2025
CVE-2020-6308

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary...

SAP BusinessObjects Business Intelligence Platform (Web Services) High Beyond CISA 20 Oct 2020

Showing 20 of 20 SAP known exploited vulnerabilities.

Recurring weakness patterns

Limitation, missing authentication for critical function, and deserialization account for eleven mapped occurrences across this SAP KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.