Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui)
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 10epss 0.7%
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
nono source reports it
SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
SAP_SE · SQL Anywhere Monitor (Non-Gui)