Vulnerability Details CVE-2025-15621
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 1.3%
CVSS Severity
CVSS v3 Score 6.0
Products affected by CVE-2025-15621
-
cpe:2.3:a:sparxsystems:enterprise_architect:16.1.1627
-
cpe:2.3:a:sparxsystems:enterprise_architect:16.1.1628
-
cpe:2.3:a:sparxsystems:enterprise_architect:16.1.1629
-
cpe:2.3:a:sparxsystems:enterprise_architect:17.0.1703
-
cpe:2.3:a:sparxsystems:enterprise_architect:17.0.1704
-
cpe:2.3:a:sparxsystems:enterprise_architect:17.1.1710
-
cpe:2.3:a:sparxsystems:enterprise_architect:17.1.1711
-
cpe:2.3:a:sparxsystems:enterprise_architect:17.1.1712
-
cpe:2.3:a:sparxsystems:enterprise_architect:17.1.1713