Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› SAP SQL Anywhere Monitor Hard-Coded Credentials 2025: Why…
Breach analysis Incident: 11 Nov 2025

SAP SQL Anywhere Monitor Hard-Coded Credentials 2025: Why CVE-2025-42890 Scored a Maximum 10.0

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 6 min read
On this page

On 11 November 2025, SAP's monthly security update fixed CVE-2025-42890, a vulnerability in the non-GUI version of SQL Anywhere Monitor that received the maximum CVSS score of 10.0. The cause was hard-coded credentials. "SQL Anywhere Monitor (Non-GUI) baked credentials into the code, exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution," the flaw's description says. SQL Anywhere Monitor is a database monitoring and alerting tool, and its non-GUI component typically runs on unattended appliances with little human oversight. SAP's fix was drastic: according to Onapsis, it removed SQL Anywhere Monitor entirely, and it advised customers who could not patch immediately to stop using the monitor and delete any instances of its database. No exploitation had been detected, and Arctic Wolf noted that the credentials had not been posted publicly.

Key takeaways

  • SAP SQL Anywhere Monitor (Non-GUI) contained hard-coded credentials, tracked as CVE-2025-42890 with a CVSS score of 10.0.
  • An attacker who obtained the credentials could reach administrative functions and potentially execute arbitrary code, according to SAP's description.
  • SAP removed SQL Anywhere Monitor in its fix; the interim workaround was to stop using it and delete its database instances.
  • No active exploitation was detected at release, and the credentials had not been published, Arctic Wolf said.
  • The identity lesson: credentials compiled into software are shared by every installation and cannot be rotated by customers, so the only fix is removal.

At a glance

OrganisationsSAP; organisations running SQL Anywhere Monitor (Non-GUI) 17.0
WhenFixed in SAP's November 2025 security updates, 11 November 2025
AttackerNone known
Entry pointCredentials hard-coded in the SQL Anywhere Monitor (Non-GUI) software
Identities abusedBuilt-in credentials shared by every installation
ImpactPotential unauthenticated access and arbitrary code execution; no exploitation detected
CategoryNHI. Incident class: vulnerability found by researchers (vulnerability, no confirmed breach)

What happened

SAP's November 2025 security updates included 18 new and one updated security note, SecurityWeek reported. The most severe was CVE-2025-42890 in SQL Anywhere Monitor, which SecurityWeek said SAP described as "an insecure key and secret management vulnerability." BleepingComputer explained that, depending on how they are used, an attacker who obtains the credentials can use them to access administrative functions, and that the non-GUI monitor "is typically deployed on unattended appliances where it runs without frequent human oversight."

Arctic Wolf, citing Onapsis, reported that SAP's patch "removes the SQL Anywhere Monitor completely." SecurityWeek quoted Onapsis on the interim advice: "As a temporary workaround, SAP recommends to stop using SQL Anywhere Monitor and to delete any instances of SQL Anywhere Monitor database." The same release fixed CVE-2025-42887, a 9.9-rated code injection flaw in SAP Solution Manager.

"At the time of writing, the hard-coded credentials have not been posted publicly, nor is there evidence suggesting that this vulnerability is being actively exploited in the wild," Arctic Wolf wrote on 11 November, while warning that SAP products have been targeted before. BleepingComputer likewise reported that no active exploitation had been detected for the two critical flaws.

Timeline

DateEvent
11 November 2025SAP releases its November security updates, fixing CVE-2025-42890.
11 November 2025BleepingComputer, SecurityWeek and Arctic Wolf report the flaw.

How it happened: the identity attack path

  1. Credentials in code. The monitor shipped with built-in credentials.
  2. Shared everywhere. Every installation used the same credentials, which customers could not change.
  3. Discovery risk. Anyone who extracted the credentials could use them against any installation.
  4. Privileged access. The credentials could reach administrative functions.
  5. Code execution. SAP's description warns of possible arbitrary code execution.

Impact

  • Potential: unauthenticated administrative access and arbitrary code execution on affected systems.
  • Exploitation: none detected at release.
  • Remediation: SQL Anywhere Monitor removed; interim advice to stop using it and delete its databases.

What this means for NHI governance

Hard-coded credentials are non-human identities without an owner on the customer side. They cannot be seen in an inventory, rotated or disabled, and they are identical on every system running the product. When they are discovered, every installation is exposed at once, which is why this flaw scored 10.0 and why SAP chose to remove the component rather than patch it. The non-GUI monitor's typical placement on unattended appliances adds to the risk: nobody is watching.

For software buyers, secure credential handling should be part of vendor assessment. For operators, the practical steps are inventorying monitoring and management tools, applying vendor removals quickly and isolating tools that run with little oversight. See our Secrets Management Guide and Service Account Security Guide.

Recommendations

  • Apply SAP's November 2025 update. Remove SQL Anywhere Monitor as the patch does.
  • If you cannot patch, stop and delete. Stop using the monitor and delete its database instances, as SAP advised.
  • Inventory unattended tools. Monitoring and management components often run with privileged, unmonitored access. See the Service Account Security Guide.
  • Restrict network exposure. Limit who can reach database monitoring services.
  • Ask vendors about embedded credentials. Include credential handling in software assessments. See our Secrets Management Guide.

Frequently asked questions

What is CVE-2025-42890?

A vulnerability in SAP SQL Anywhere Monitor (Non-GUI) caused by hard-coded credentials, rated CVSS 10.0. It could allow attackers to reach administrative functions and potentially execute code.

How did SAP fix CVE-2025-42890?

SAP removed SQL Anywhere Monitor entirely in its November 2025 update. Customers who cannot patch should stop using the monitor and delete its database instances.

Was CVE-2025-42890 exploited?

No exploitation had been detected when the fix was released, and the credentials had not been published, according to Arctic Wolf.

HPE Aruba Hard-Coded Credentials 2025 · ASP.NET Machine Key Attacks 2025 · Secrets Management Guide · Service Account Security Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Embedded and built-in credentials are the hardest non-human identities to see. We help teams inventory unattended tools, track vendor credential issues and act quickly on removals. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org