CVE-2025-15621 PUBLISHED

Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication

Assigner: NCSC-FI
Reserved: 09.04.2026 Published: 16.04.2026 Updated: 16.04.2026

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/S:P/AU:Y/V:C/RE:M
CVSS Score: 5.7

Product Status

Vendor Sparx Systems Pty Ltd.
Product Sparx Enterprise Architect
Versions Default: unknown
  • Version 16.1.1627 is affected
  • Version 17.1.1714 is unaffected

Solutions

Update to fixed version

Credits

  • Pasi Orovuo, Solita Oy finder
  • Henri Hämäläinen, Solita Oy finder
  • Samu Ahvenainen, Solita Oy finder

References

Problem Types

  • CWE-522: Insufficiently Protected Credentials CWE