ZeroHour

CVE-2025-15621

CVSS 4.0
5.7 medium
EPSS
<1%p1
Published
()
Modified
Description

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

Vendors
sparxsystems
Products
enterprise architect
Weakness
CWE-522
Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:C/RE:M/U:X

In the news

No ingested article mentions this CVE yet.