CVE-2025-67805

A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposing sensitive information such as hashes and table names. This feature is disabled by default in all installations and never available in Sage DPW Cloud. It was forcibly disabled again in version 2025_06_003.
References
Link Resource
https://pastebin.com/Tk4LgMG2 Third Party Advisory
https://www.sagedpw.at/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:sagedpw:sage_dpw:2025_06_004:*:*:*:*:*:*:*

History

10 May 2026, 14:16

Type Values Removed Values Added
CWE CWE-200

07 Apr 2026, 19:39

Type Values Removed Values Added
References () https://pastebin.com/Tk4LgMG2 - () https://pastebin.com/Tk4LgMG2 - Third Party Advisory
References () https://www.sagedpw.at/ - () https://www.sagedpw.at/ - Product
CPE cpe:2.3:a:sagedpw:sage_dpw:2025_06_004:*:*:*:*:*:*:*
First Time Sagedpw sage Dpw
Sagedpw
CWE CWE-306

01 Apr 2026, 16:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 16:23

Updated : 2026-05-10 14:16


NVD link : CVE-2025-67805

Mitre link : CVE-2025-67805

CVE.ORG link : CVE-2025-67805


JSON object : View

Products Affected

sagedpw

  • sage_dpw
CWE
CWE-306

Missing Authentication for Critical Function

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor