SAP SE vendor intelligence

SAP SE Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting SAP SE products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse SAP SE KEVs Full KEV feed
Total KEVs
10
Known exploited vulnerabilities affecting SAP SE products
In CISA KEV
6
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited CVEs absent from CISA KEV
Sensor Observed
2
SAP SE KEVs with sensor-observed exploitation activity

The catalog gap matters for SAP SE exposure

Four of the ten exploited SAP SE CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 40% of this vendor portfolio.

60%
Covered by CISA
40%
Beyond CISA
9
Product families

Attested SAP SE CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2020-6286

The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30,...

SAP NetWeaver AS JAVA (LM Configuration Wizard) Confirmed Beyond CISA 12 Jun 2026
CVE-2021-21479

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the...

SCIMono High Beyond CISA 27 Jul 2025
CVE-2021-33690

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions...

SAP NetWeaver Development Infrastructure (Component Build Service) High Beyond CISA 11 Jul 2025
CVE-2020-6207

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a...

SAP Solution Manager (User Experience Monitoring) Confirmed In CISA 03 Nov 2021
CVE-2020-6287

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an...

SAP NetWeaver AS JAVA (LM Configuration Wizard) Confirmed In CISA 03 Nov 2021
CVE-2018-2380

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus...

SAP CRM Confirmed In CISA 03 Nov 2021
CVE-2021-38163

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative...

SAP NetWeaver (Visual Composer 7.0 RT) Confirmed In CISA 09 Jun 2022
CVE-2022-22536

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are...

SAP NetWeaver and ABAP Platform, SAP Web Dispatcher, SAP Content Server Confirmed In CISA 18 Aug 2022
CVE-2019-0344

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to...

SAP Commerce Cloud (virtualjdbc extension) Confirmed In CISA 30 Sep 2024
CVE-2020-6308

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary...

SAP BusinessObjects Business Intelligence Platform (Web Services) High Beyond CISA 20 Oct 2020

Showing 10 of 10 SAP SE known exploited vulnerabilities.

Recurring weakness patterns

Limitation, missing authentication for critical function, and server-side request forgery (ssrf) account for seven mapped occurrences across this SAP SE KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.