SAP fixes hardcoded credentials flaw in SQL Anywhere Monitor
ID: fc88f74b-736f-5312-ae4a-ba485b6c412f
STIX ID: report--fc88f74b-736f-5312-ae4a-ba485b6c412f
Feed Name: Bleeping Computer
SAP released November 2025 security updates addressing multiple vulnerabilities, including two critical flaws: CVE-2025-42890 (hardcoded credentials in SQL Anywhere Monitor, rated 10.0, enabling potential arbitrary code execution and administrative access) and CVE-2025-42887 (code-injection in SAP Solution Manager, rated 9.9, allowing authenticated attackers to execute malicious code). The advisory notes additional fixes for high and medium severity issues, states there is no observed active exploitation for the two critical flaws, and urges administrators to apply vendor updates and mitigations promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
