On 11 November 2025, SAP's monthly security update fixed CVE-2025-42890, a vulnerability in the non-GUI version of SQL Anywhere Monitor that received the maximum CVSS score of 10.0. The cause was hard-coded credentials. "SQL Anywhere Monitor (Non-GUI) baked credentials into the code, exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution," the flaw's description says. SQL Anywhere Monitor is a database monitoring and alerting tool, and its non-GUI component typically runs on unattended appliances with little human oversight. SAP's fix was drastic: according to Onapsis, it removed SQL Anywhere Monitor entirely, and it advised customers who could not patch immediately to stop using the monitor and delete any instances of its database. No exploitation had been detected, and Arctic Wolf noted that the credentials had not been posted publicly.
Key takeaways
- SAP SQL Anywhere Monitor (Non-GUI) contained hard-coded credentials, tracked as CVE-2025-42890 with a CVSS score of 10.0.
- An attacker who obtained the credentials could reach administrative functions and potentially execute arbitrary code, according to SAP's description.
- SAP removed SQL Anywhere Monitor in its fix; the interim workaround was to stop using it and delete its database instances.
- No active exploitation was detected at release, and the credentials had not been published, Arctic Wolf said.
- The identity lesson: credentials compiled into software are shared by every installation and cannot be rotated by customers, so the only fix is removal.
At a glance
| Organisations | SAP; organisations running SQL Anywhere Monitor (Non-GUI) 17.0 |
|---|---|
| When | Fixed in SAP's November 2025 security updates, 11 November 2025 |
| Attacker | None known |
| Entry point | Credentials hard-coded in the SQL Anywhere Monitor (Non-GUI) software |
| Identities abused | Built-in credentials shared by every installation |
| Impact | Potential unauthenticated access and arbitrary code execution; no exploitation detected |
| Category | NHI. Incident class: vulnerability found by researchers (vulnerability, no confirmed breach) |
What happened
SAP's November 2025 security updates included 18 new and one updated security note, SecurityWeek reported. The most severe was CVE-2025-42890 in SQL Anywhere Monitor, which SecurityWeek said SAP described as "an insecure key and secret management vulnerability." BleepingComputer explained that, depending on how they are used, an attacker who obtains the credentials can use them to access administrative functions, and that the non-GUI monitor "is typically deployed on unattended appliances where it runs without frequent human oversight."
Arctic Wolf, citing Onapsis, reported that SAP's patch "removes the SQL Anywhere Monitor completely." SecurityWeek quoted Onapsis on the interim advice: "As a temporary workaround, SAP recommends to stop using SQL Anywhere Monitor and to delete any instances of SQL Anywhere Monitor database." The same release fixed CVE-2025-42887, a 9.9-rated code injection flaw in SAP Solution Manager.
"At the time of writing, the hard-coded credentials have not been posted publicly, nor is there evidence suggesting that this vulnerability is being actively exploited in the wild," Arctic Wolf wrote on 11 November, while warning that SAP products have been targeted before. BleepingComputer likewise reported that no active exploitation had been detected for the two critical flaws.
Timeline
| Date | Event |
|---|---|
| 11 November 2025 | SAP releases its November security updates, fixing CVE-2025-42890. |
| 11 November 2025 | BleepingComputer, SecurityWeek and Arctic Wolf report the flaw. |
How it happened: the identity attack path
- Credentials in code. The monitor shipped with built-in credentials.
- Shared everywhere. Every installation used the same credentials, which customers could not change.
- Discovery risk. Anyone who extracted the credentials could use them against any installation.
- Privileged access. The credentials could reach administrative functions.
- Code execution. SAP's description warns of possible arbitrary code execution.
Impact
- Potential: unauthenticated administrative access and arbitrary code execution on affected systems.
- Exploitation: none detected at release.
- Remediation: SQL Anywhere Monitor removed; interim advice to stop using it and delete its databases.
What this means for NHI governance
Hard-coded credentials are non-human identities without an owner on the customer side. They cannot be seen in an inventory, rotated or disabled, and they are identical on every system running the product. When they are discovered, every installation is exposed at once, which is why this flaw scored 10.0 and why SAP chose to remove the component rather than patch it. The non-GUI monitor's typical placement on unattended appliances adds to the risk: nobody is watching.
For software buyers, secure credential handling should be part of vendor assessment. For operators, the practical steps are inventorying monitoring and management tools, applying vendor removals quickly and isolating tools that run with little oversight. See our Secrets Management Guide and Service Account Security Guide.
Recommendations
- Apply SAP's November 2025 update. Remove SQL Anywhere Monitor as the patch does.
- If you cannot patch, stop and delete. Stop using the monitor and delete its database instances, as SAP advised.
- Inventory unattended tools. Monitoring and management components often run with privileged, unmonitored access. See the Service Account Security Guide.
- Restrict network exposure. Limit who can reach database monitoring services.
- Ask vendors about embedded credentials. Include credential handling in software assessments. See our Secrets Management Guide.
Frequently asked questions
What is CVE-2025-42890?
A vulnerability in SAP SQL Anywhere Monitor (Non-GUI) caused by hard-coded credentials, rated CVSS 10.0. It could allow attackers to reach administrative functions and potentially execute code.
How did SAP fix CVE-2025-42890?
SAP removed SQL Anywhere Monitor entirely in its November 2025 update. Customers who cannot patch should stop using the monitor and delete its database instances.
Was CVE-2025-42890 exploited?
No exploitation had been detected when the fix was released, and the credentials had not been published, according to Arctic Wolf.
Related NHI Mgmt Group resources
HPE Aruba Hard-Coded Credentials 2025 · ASP.NET Machine Key Attacks 2025 · Secrets Management Guide · Service Account Security Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Embedded and built-in credentials are the hardest non-human identities to see. We help teams inventory unattended tools, track vendor credential issues and act quickly on removals. See our NHI and AI agent security training.
References
- BleepingComputer: SAP fixes hardcoded credentials flaw in SQL Anywhere Monitor (11 November 2025)
- SecurityWeek: SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager (11 November 2025)
- Arctic Wolf: CVE-2025-42890: Hard-Coded Credentials in SAP SQL Anywhere Monitor (Non-GUI) (11 November 2025)