Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Advisories

No advisories yet.

Fixes

Solution

Update to fixed version


Workaround

No workaround given by the vendor.

History

Thu, 16 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Apr 2026 12:45:00 +0000

Type Values Removed Values Added
Description Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Title Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/S:P/AU:Y/V:C/RE:M'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC-FI

Published:

Updated: 2026-04-16T12:51:51.633Z

Reserved: 2026-04-09T08:02:25.619Z

Link: CVE-2025-15621

cve-icon Vulnrichment

Updated: 2026-04-16T12:51:47.736Z

cve-icon NVD

Status : Received

Published: 2026-04-16T13:16:43.423

Modified: 2026-04-16T13:16:43.423

Link: CVE-2025-15621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses