A critical vulnerability, tracked as CVE-2025-42890, was discovered in the non-GUI variant of SAP's SQL Anywhere Monitor. The flaw stems from hardcoded credentials being embedded in the application's code, which exposes sensitive resources and functionality to unauthorized users. This vulnerability allows attackers to potentially achieve arbitrary code execution, posing a severe risk to the confidentiality, integrity, and availability of affected systems. The vulnerability has been assigned the maximum CVSS score of 10.0, highlighting its critical nature and the urgency for remediation.
SAP addressed this issue in its November security updates, which also included fixes for other high-severity vulnerabilities. The SQL Anywhere Monitor is commonly used by organizations to oversee distributed or remote databases, and the non-GUI component is often deployed on unattended appliances, increasing the risk of exploitation due to limited oversight. SAP has urged customers to apply the security updates promptly to mitigate the risk associated with this flaw and prevent potential unauthorized access or system compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
As part of the fix for CVE-2025-42890, SAP's patch removed SQL Anywhere Monitor entirely. SAP also advised customers unable to patch immediately to stop using SQL Anywhere Monitor and delete existing monitor database instances as a temporary mitigation.
On 2025-11-11, SAP published a security advisory as part of its November 2025 updates for CVE-2025-42890, a maximum-severity hardcoded-credentials flaw in SQL Anywhere Monitor (Non-GUI) version 17.0. The vulnerability could allow unauthenticated access and arbitrary code execution, and SAP stated there was no evidence of active exploitation at disclosure time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecvefeed.io
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcearcticwolf.com
Open sourcearcticwolf.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.