VulnerabilityAnalyzed
CVE-2025-15621
Insufficiently Protected Credentials in Sparx Systems Pty Ltd.
MEDIUM 5.7EPSS 0.11%
Does this matter?
Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
- CVSS 4.0
- 5.7 MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.11% probability · 1th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- sparxsystems/enterprise architect
- Source
- db4dfee8-a97e-4877-bfae-eba6d14a2166
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.