Overview
The Sage DPW Database Monitor could be accessed directly without a valid session, allowing external users to inspect internal database structures and operational information.
Technical findings
Although the DB Monitor was part of an administrative web area, a direct request did not trigger effective session validation. The interface was returned even without a session cookie.
Exposed information included tables, indexes, record counts and current database activity. This is sensitive in its own right and also valuable reconnaissance material.
The lesson is straightforward: a function is not protected merely because users normally reach it from an admin menu. The server must authorize direct requests too.
Why it matters
An attacker could query the monitoring endpoint directly. Visible tables, object names and runtime information simplify reconnaissance and can make follow-on attacks more targeted.
Potential impact
- Unauthenticated access to DB monitoring and administration endpoints can disclose internal information.
Remediation
- Upgrade to Sage DPW 2025_06_000 or later.
- Enforce server-side session and role checks on every administrative endpoint.
- Remove diagnostic and monitoring components from production unless strictly necessary.
- Restrict administrative areas further through network segmentation or dedicated management networks.
Affected and fixed versions
Disclosure timeline
- Discovery
Identified during an external penetration test.
- Initial contact
Initiated the disclosure process with Sage.
- Full report
Submitted the coordinated disclosure report to Sage.
- Vendor discussion
Discussed findings, CVSS ratings and the retest approach.
- Independent CVSS review
CERT.at largely confirmed the original ratings.
- Fix plan
Sage identified 2025_06_000 as the target release.
- Fix release
The fixes were released.
- Final disclosure announcement
Announced public disclosure and addressed outstanding questions.
- Public Disclosure
The CVE was published publicly.