CVE-2025-51532

7.5

Sage · DPW

An incorrect access control vulnerability in Sage DPW allows unauthenticated attackers to access the built-in Database Monitor via a crafted request.

Executive summary

A critical access control flaw in Sage DPW allows unauthenticated remote attackers to access sensitive database monitoring functions, posing a significant risk to data confidentiality.

Vulnerability

This vulnerability is an incorrect access control issue that permits unauthenticated users to reach the internal Database Monitor by sending a specifically crafted network request. The CVSS vector confirms that no privileges are required to exploit this flaw over the network.

Business impact

The ability for an unauthenticated attacker to view the Database Monitor can lead to the exposure of sensitive system information, configuration details, or potentially proprietary data stored within the database. With a CVSS score of 7.5, this high-severity vulnerability represents a substantial threat to organizational data security and compliance posture.

Remediation

Immediate Action: Update Sage DPW to version 2025_06_000 or later to apply the vendor-supplied security fix.

Proactive Monitoring: Review web server and application access logs for unusual requests targeting the Database Monitor endpoint or suspicious access patterns from unknown IP addresses.

Compensating Controls: Implement strict network segmentation or Web Application Firewall (WAF) rules to restrict access to the Sage DPW management interfaces to authorized internal IP ranges only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the exposure of administrative database functions to unauthenticated attackers, organizations must prioritize the application of the 2025_06_000 update. Until patching is completed, ensure that the application is not exposed to the public internet and restrict access via firewall rules to minimize the attack surface.

Sources