CVE-2025-15622 PUBLISHED

Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret

Assigner: NCSC-FI
Reserved: 09.04.2026 Published: 17.04.2026 Updated: 17.04.2026

Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N/S:P/AU:Y/V:C/RE:M/U:Red
CVSS Score: 6.2

Product Status

Vendor Sparx Systems Pty Ltd.
Product Sparx Enterprise Architect
Versions Default: unknown
  • Version 16.1.1627 is affected
  • Version 17.1.1714 is unaffected

Solutions

Update to fixed version

Credits

  • Pasi Orovuo, Solita Oy finder
  • Henri Hämäläinen, Solita Oy finder
  • Samu Ahvenainen, Solita Oy finder

References

Problem Types

  • CWE-522: Insufficiently Protected Credentials CWE