SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap sql Anywhere |
|
| Vendors & Products |
Sap
Sap sql Anywhere |
Tue, 11 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system. | |
| Title | Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui) | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-11-11T00:15:29.439Z
Updated: 2025-11-12T04:57:41.298Z
Reserved: 2025-04-16T13:25:19.826Z
Link: CVE-2025-42890
No data.
Status : Awaiting Analysis
Published: 2025-11-11T01:15:37.820
Modified: 2025-11-12T16:19:59.103
Link: CVE-2025-42890
No data.