CVE 5.7 MEDIUM

Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication_CVE-2025-15621

5.7 / 10
MEDIUM
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/S:P/AU:Y/V:C/RE:M

Description

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

Basic Information

ID CVE-2025-15621
Source NCSC-FI
Published Apr 16, 2026 at 12:40
Modified Apr 16, 2026 at 12:51

Affected Product

Vendor Sparx Systems Pty Ltd.
Product Sparx Enterprise Architect
Version 16.1.1627
Affected Versions Sparx Systems Pty Ltd. Sparx Enterprise Architect 16.1.1627

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.