Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update to fixed version
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://sparxsystems.com/products/ea/17.1/history.html |
|
History
Fri, 17 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow. | |
| Title | Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NCSC-FI
Published:
Updated: 2026-04-17T08:35:05.019Z
Reserved: 2026-04-09T08:02:28.850Z
Link: CVE-2025-15622
No data.
Status : Received
Published: 2026-04-17T09:16:03.633
Modified: 2026-04-17T09:16:03.633
Link: CVE-2025-15622
No data.
OpenCVE Enrichment
Updated: 2026-04-17T10:30:12Z
Weaknesses