# CVE-2025-42890

## Summary

- **CVE ID:** CVE-2025-42890
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-798
- **Published:** Nov 11, 2025
- **Last Modified:** Mar 13, 2026

## Description

SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.

## Affected Products

- SAP_SE — SQL Anywhere Monitor (Non-Gui) (SYBASE_SQL_ANYWHERE_SERVER 17.0)

## References

- [CNA](https://me.sap.com/notes/3666261)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.69%
- **EPSS Percentile:** 50.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._