Project Subscriptions
No data.
No advisories yet.
Solution
Update to fixed version
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://sparxsystems.com/products/ea/17.1/history.html |
|
Fri, 17 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow. | |
| Title | Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NCSC-FI
Published:
Updated: 2026-04-17T12:56:53.740Z
Reserved: 2026-04-09T08:02:28.850Z
Link: CVE-2025-15622
Updated: 2026-04-17T12:50:48.107Z
Status : Received
Published: 2026-04-17T09:16:03.633
Modified: 2026-04-17T09:16:03.633
Link: CVE-2025-15622
No data.
OpenCVE Enrichment
Updated: 2026-04-17T10:30:12Z