SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.
History

Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap sql Anywhere
Vendors & Products Sap
Sap sql Anywhere

Tue, 11 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.
Title Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui)
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-11-11T00:15:29.439Z

Updated: 2025-11-12T04:57:41.298Z

Reserved: 2025-04-16T13:25:19.826Z

Link: CVE-2025-42890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T01:15:37.820

Modified: 2025-11-12T16:19:59.103

Link: CVE-2025-42890

cve-icon Redhat

No data.