logo

SAP fixes hardcoded credentials flaw in SQL Anywhere Monitor

ID: fc88f74b-736f-5312-ae4a-ba485b6c412f

STIX ID: report--fc88f74b-736f-5312-ae4a-ba485b6c412f

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-11-11

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

SAP released November 2025 security updates addressing multiple vulnerabilities, including two critical flaws: CVE-2025-42890 (hardcoded credentials in SQL Anywhere Monitor, rated 10.0, enabling potential arbitrary code execution and administrative access) and CVE-2025-42887 (code-injection in SAP Solution Manager, rated 9.9, allowing authenticated attackers to execute malicious code). The advisory notes additional fixes for high and medium severity issues, states there is no observed active exploitation for the two critical flaws, and urges administrators to apply vendor updates and mitigations promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.