CVE-2025-67805

A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposing sensitive information such as hashes and table names. This feature is disabled by default in all installations and never available in Sage DPW Cloud. It was forcibly disabled again in version 2025_06_003.
References
Link Resource
https://pastebin.com/Tk4LgMG2 Third Party Advisory
https://www.sagedpw.at/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:sagedpw:sage_dpw:2025_06_004:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-01 16:23

Updated : 2026-06-17 09:58


NVD link : CVE-2025-67805

Mitre link : CVE-2025-67805

CVE.ORG link : CVE-2025-67805


JSON object : View

Products Affected

sagedpw

  • sage_dpw
CWE
CWE-306

Missing Authentication for Critical Function

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor