CVE-2025-15624

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sparxsystems:pro_cloud_server:6.0.163:*:*:*:*:*:*:*

History

02 Jun 2026, 14:26

Type Values Removed Values Added
First Time Sparxsystems pro Cloud Server
Sparxsystems
References () https://sparxsystems.com/products/procloudserver/6.1/history.html - () https://sparxsystems.com/products/procloudserver/6.1/history.html - Release Notes
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:sparxsystems:pro_cloud_server:6.0.163:*:*:*:*:*:*:*

17 Apr 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-17 09:16

Updated : 2026-06-02 14:26


NVD link : CVE-2025-15624

Mitre link : CVE-2025-15624

CVE.ORG link : CVE-2025-15624


JSON object : View

Products Affected

sparxsystems

  • pro_cloud_server
CWE
CWE-256

Plaintext Storage of a Password