Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://sparxsystems.com/products/ea/17.1/history.html |
|
History
Fri, 17 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow. | |
| Title | Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC-FI
Published:
Updated: 2026-04-17T12:56:53.740Z
Reserved: 2026-04-09T08:02:28.850Z
Link: CVE-2025-15622
Updated: 2026-04-17T12:50:48.107Z
Status : Received
Published: 2026-04-17T09:16:03.633
Modified: 2026-04-17T09:16:03.633
Link: CVE-2025-15622
No data.
OpenCVE Enrichment
Updated: 2026-04-17T10:30:12Z