Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://sparxsystems.com/products/ea/17.1/history.html |
Configurations
No configuration.
History
17 Apr 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-17 09:16
Updated : 2026-04-17 15:13
NVD link : CVE-2025-15622
Mitre link : CVE-2025-15622
CVE.ORG link : CVE-2025-15622
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials
