CVE-2025-13774
8.8Progress Software · Flowmon ADS
A SQL injection vulnerability in Progress Flowmon ADS allows authenticated users to execute unauthorized SQL queries and commands.
Executive summary
Progress Flowmon ADS contains a critical SQL injection vulnerability that allows authenticated attackers to compromise the integrity and availability of the database.
Vulnerability
The application is susceptible to SQL injection (CWE-89) because it fails to properly neutralize special elements used in SQL commands. This flaw allows an authenticated user to perform unauthorized database operations through crafted queries.
Business impact
The ability for an authenticated user to execute arbitrary SQL commands poses a severe risk to organizational data. Successful exploitation could lead to unauthorized data exfiltration, modification of sensitive records, or total system disruption, justifying the high CVSS score of 8.8. Such an impact threatens both operational continuity and the confidentiality of monitored network traffic data.
Remediation
Immediate Action: Upgrade to Flowmon ADS version 12.5.4, 13.0.1, or later versions as specified by the vendor security advisory.
Proactive Monitoring: Review system and database access logs for unusual query patterns, unexpected error messages, or unauthorized administrative actions.
Compensating Controls: Implement a Web Application Firewall (WAF) with updated rulesets designed to detect and block common SQL injection patterns targeting the application environment.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS severity and the potential for full database compromise, administrators must prioritize this update. Ensure that all Flowmon ADS instances are patched to the specified versions immediately to neutralize the SQL injection vector. Secondary focus should be placed on auditing current user access levels to minimize the risk of unauthorized exploitation.