Unauthorized Access Vulnerability in Sage DPW Database Monitor
CVE-2025-67805

5.9MEDIUM

Key Information:

Vendor

Sage

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2025-67805?

The configuration in Sage DPW 2025_06_004 permits unauthenticated access to the Database Monitor feature, potentially leaking sensitive information like database table names and hashes. This feature, although non-default and disabled in standard installations, raises concerns about security practices. The vulnerability is not present in Sage DPW Cloud, and previous updates have reiterated measures to mitigate this risk, including a disabling mechanism in version 2025_06_003.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.