Aller au contenu

Fiche vulnérabilité

CVE-2025-15624 : faille élevée sparxsystems pro cloud server (CVSS 7.5)

Description

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
17 avr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • sparxsystems pro cloud server

Références

Rechercher une autre vulnérabilité dans la base CVE