Advisory
On 11.11.2025 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within Sybase platform.
SAP Note 3666261 addresses "[CVE-2025-42890] Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui)" to prevent insecure storage of sensitive data (password) with a hot news risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
The SQL Anywhere Monitor (non-GUI) contains a flaw that allows an unauthenticated attacker to access certain resources or functions, potentially enabling remote code execution and leading to unauthorized access to the server.Solution
The SQL Anywhere Monitor has been removed to prevent unauthorized access. Existing installations will delete the database located in the default installation paths and will provide the unloaded historical data.
