Vulnerability Intelligence Report
Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui)
CVE-2025-42890
SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:0.63%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-798 ↗CWE-798: Use of Hard-coded Credentials
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SAP_SE | SQL Anywhere Monitor (Non-Gui) | SYBASE_SQL_ANYWHERE_SERVER 17.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.633%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SAP SE · Vendor · Germany |
| Reserved | 2025-04-16T13:25:19 |
| Published | 2025-11-11T00:15:29 |
| Last Updated | 2026-02-26T17:46:57 |
Community Chatter & Buzz