SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-15621

Insufficiently Protected Credentials in Sparx Systems Pty Ltd.

MEDIUM 5.7EPSS 0.11%

Does this matter?

Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.

Description

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

CVSS 4.0
5.7 MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.11% probability · 1th percentile
CISA KEV
Not listed
Weakness
CWE-522
Affected
sparxsystems/enterprise architect
Source
db4dfee8-a97e-4877-bfae-eba6d14a2166

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.