CVE-2022-47072: Sparxsystems Enterprise Architect

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..

Affected products

Published 2024-01-31. Last modified 2026-06-17.