CVE-2025-42890: Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui)
SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42890?
CVE-2025-42890 has a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2025-42890?
To fix CVE-2025-42890, update to the latest version of SAP SQL Anywhere Monitor (Non-GUI) that addresses this vulnerability.
What are the potential impacts of CVE-2025-42890?
CVE-2025-42890 can significantly affect system confidentiality, integrity, and availability.
Who is affected by CVE-2025-42890?
CVE-2025-42890 affects users of SAP SQL Anywhere Monitor (Non-GUI) who are using the vulnerable version.
Can CVE-2025-42890 lead to data breaches?
Yes, CVE-2025-42890 could lead to data breaches due to exposed credentials that allow unauthorized access.