PT-2025-46231 · Sap · Sql Anywhere Monitor

Published

2025-11-11

·

Updated

2025-11-16

·

CVE-2025-42890

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SQL Anywhere Monitor (Non-GUI) version 17.0 versions prior to SAP Note 3666261
Description The SQL Anywhere Monitor (Non-GUI) contains hard-coded credentials within its code. This allows unintended users access to resources and functionality, potentially leading to arbitrary code execution. The issue has a critical impact on the confidentiality, integrity, and availability of the system. The vulnerability allows attackers to gain unauthorized access without authentication.
Recommendations Apply SAP Note 3666261. Rotate all related credentials. As a temporary workaround, discontinue the use of the monitor and delete all database instances.

Fix

RCE

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-14425
CVE-2025-42890

Affected Products

Sql Anywhere Monitor