VDB

GCVE-110-NCSC-2025-356

GCVE-110-NCSC-2025-356
Advisory PublishedCVSS 10.0/10
Vulnetix · Advisory published November 11, 2025
The SQL Anywhere Monitor (Non-GUI) contains baked credentials and vulnerabilities related to insecure key and secret management, posing significant risks to system confidentiality, integrity, and availability.

Weaknesses (CWE)

CWE-798Use of Hard-coded CredentialsCWE-502Deserialization of Untrusted DataCWE-94Improper Control of Generation of Code ('Code Injection')CWE-787Out-of-bounds WriteCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-943Improper Neutralization of Special Elements in Data Query LogicCWE-601URL Redirection to Untrusted Site ('Open Redirect')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-306Missing Authentication for Critical FunctionCWE-316Cleartext Storage of Sensitive Information in MemoryCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-522Insufficiently Protected CredentialsCWE-862Missing AuthorizationCWE-434Unrestricted Upload of File with Dangerous Type

Risk Scores

CVSS 3.1
10.0/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
SAPvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,557 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›