CVE-2025-15622

Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Apr 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-17 09:16

Updated : 2026-04-17 15:13


NVD link : CVE-2025-15622

Mitre link : CVE-2025-15622

CVE.ORG link : CVE-2025-15622


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials