MEDIUM · 6.0

CVE-2025-15621

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

Vulnerability Description

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

CVSS Score

6.0

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
SparxsystemsEnterprise Architect>= 16.1.1627, < 17.1.1714

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-15621?

CVE-2025-15621 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

How severe is CVE-2025-15621?

CVE-2025-15621 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-15621?

Check the references section above for vendor advisories and patch information. Affected products include: Sparxsystems Enterprise Architect.