diff --git a/.github/dependabot.yaml b/.github/dependabot.yaml
index b70a988ef..73be63d7b 100644
--- a/.github/dependabot.yaml
+++ b/.github/dependabot.yaml
@@ -36,6 +36,15 @@ updates:
- dependency-name: 'com.github.ekryd.sortpom:sortpom-maven-plugin'
# used by deprecated code only, not worth updating for now
- dependency-name: 'org.apache.axis2:*'
+ # Ignore problematic license versions
+ - dependency-name: 'com.sap.cloud.security:java-security'
+ versions: ['3.6.1', '3.6.2']
+ - dependency-name: 'com.sap.cloud.security.xsuaa:token-client'
+ versions: ['3.6.1', '3.6.2']
+ - dependency-name: 'com.sap.cloud.security:java-api'
+ versions: ['3.6.1', '3.6.2']
+ - dependency-name: 'com.sap.cloud.security:env'
+ versions: ['3.6.1', '3.6.2']
# archetype updates
# Dependabot seems to be unable to handle those, so this is disabled for now
diff --git a/dependency-bundles/bom/pom.xml b/dependency-bundles/bom/pom.xml
index 7e0953650..28c152969 100644
--- a/dependency-bundles/bom/pom.xml
+++ b/dependency-bundles/bom/pom.xml
@@ -51,7 +51,7 @@
- 3.6.2
+ 3.6.0
4.5.0
2.0.17