PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-67805 Sagedpw CVE debrief

CVE-2025-67805 describes an exposure in Sage DPW 2025_06_004 where a non-default Database Monitor configuration can allow unauthenticated access to diagnostic endpoints. According to the source description, the affected endpoints can expose sensitive information such as hashes and table names. The feature is disabled by default in all installations, never available in Sage DPW Cloud, and was forcibly disabled again in version 2025_06_003.

Vendor
Sagedpw
Product
Sage Dpw
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-01
Original CVE updated
2026-05-10
Advisory published
2026-04-01
Advisory updated
2026-05-10

Who should care

Sage DPW administrators and security teams responsible for on-premises deployments, especially any environment running 2025_06_004 or any installation where the Database Monitor feature was enabled outside the default configuration.

Technical summary

NVD lists the vulnerable CPE as cpe:2.3:a:sagedpw:sage_dpw:2025_06_004 and assigns CVSS 3.1 vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N (5.9 MEDIUM). The vulnerability is described as unauthenticated access to diagnostic endpoints in the Database Monitor feature under a non-default configuration, resulting in information disclosure rather than integrity or availability impact. NVD also maps the issue to CWE-306 and CWE-200.

Defensive priority

Medium for any on-premises system where Database Monitor is enabled or could be enabled outside the default posture. Lower priority for default installations and Sage DPW Cloud based on the source description, which says the feature is disabled by default and never available in cloud deployments.

Recommended defensive actions

  • Verify whether any Sage DPW deployment uses version 2025_06_004.
  • Confirm that Database Monitor remains disabled in all non-lab environments.
  • If Database Monitor is required, restrict access to the affected diagnostic surfaces and review vendor guidance for the forced-disable behavior introduced in 2025_06_003.
  • Search for any exposure of hashes or table names through the diagnostic endpoints and rotate secrets or credentials if sensitive material was revealed.
  • Use the official CVE/NVD record and vendor materials to track any further clarification or remediation updates.

Evidence notes

Source corpus indicates: published 2026-04-01 and last modified 2026-05-10; CVSS 3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; vulnerable CPE cpe:2.3:a:sagedpw:sage_dpw:2025_06_004; references include the official CVE record, NVD detail page, a third-party advisory link, and the product site. The supplied description explicitly states the feature is disabled by default and never available in Sage DPW Cloud.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-67805 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-67805

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-67805 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-67805

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.