Aller au contenu

Fiche vulnérabilité

CVE-2025-15621 : faille moyenne sparxsystems enterprise architect (CVSS 6.0)

Description

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

En bref

Sévérité
Moyenne (CVSS 6.0)
Vecteur CVSS
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
16 avr. 2026
Dernière mise à jour
21 août 2026

Produits concernés

  • sparxsystems enterprise architect

Références

Rechercher une autre vulnérabilité dans la base CVE