Fiche vulnérabilité
CVE-2025-15621 : faille moyenne sparxsystems enterprise architect (CVSS 6.0)
Description
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
En bref
- Sévérité
- Moyenne (CVSS 6.0)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 16 avr. 2026
- Dernière mise à jour
- 21 août 2026
Produits concernés
- sparxsystems enterprise architect