Security Advisory

CVE-2025-51532Unauthenticated access to the DB Monitor admin interface

Sage DPW v8 (OnPremise) · Sage GmbH

CVE published 6 Aug 2025 · discovered 16 Apr 2025

Overview

The Sage DPW Database Monitor could be accessed directly without a valid session, allowing external users to inspect internal database structures and operational information.

Technical findings

Although the DB Monitor was part of an administrative web area, a direct request did not trigger effective session validation. The interface was returned even without a session cookie.

Exposed information included tables, indexes, record counts and current database activity. This is sensitive in its own right and also valuable reconnaissance material.

The lesson is straightforward: a function is not protected merely because users normally reach it from an admin menu. The server must authorize direct requests too.

Why it matters

An attacker could query the monitoring endpoint directly. Visible tables, object names and runtime information simplify reconnaissance and can make follow-on attacks more targeted.

Potential impact

  • Unauthenticated access to DB monitoring and administration endpoints can disclose internal information.

Remediation

  • Upgrade to Sage DPW 2025_06_000 or later.
  • Enforce server-side session and role checks on every administrative endpoint.
  • Remove diagnostic and monitoring components from production unless strictly necessary.
  • Restrict administrative areas further through network segmentation or dedicated management networks.

Affected and fixed versions

Affected<= 2024_12_004
Fixed / vendor-confirmed2025_06_000 (June 2025)

Disclosure timeline

  1. Discovery

    Identified during an external penetration test.

  2. Initial contact

    Initiated the disclosure process with Sage.

  3. Full report

    Submitted the coordinated disclosure report to Sage.

  4. Vendor discussion

    Discussed findings, CVSS ratings and the retest approach.

  5. Independent CVSS review

    CERT.at largely confirmed the original ratings.

  6. Fix plan

    Sage identified 2025_06_000 as the target release.

  7. Fix release

    The fixes were released.

  8. Final disclosure announcement

    Announced public disclosure and addressed outstanding questions.

  9. Public Disclosure

    The CVE was published publicly.

References

Related Sage DPW research