CVE-2025-15623 PUBLISHED

Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user

Assigner: NCSC-FI
Reserved: 09.04.2026 Published: 17.04.2026 Updated: 17.04.2026

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.

Unauthenticated user can retrieve database password in plaintext in certain situations

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/S:P/AU:Y/V:C/RE:M/U:Red
CVSS Score: 9.3

Product Status

Vendor Sparx Systems Pty Ltd.
Product Sparx Pro Cloud Server
Versions Default: unknown
  • Version 6.0.163 is affected

Credits

  • Pasi Orovuo, Solita Oy finder
  • Henri Hämäläinen, Solita Oy finder
  • Samu Ahvenainen, Solita Oy finder

References

Problem Types

  • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor CWE
  • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere CWE