CVE-2025-15621: Sparxsystems Enterprise Architect
Medium severity, CVSS 6.0. EPSS: 0.1% chance of exploitation in the next 30 days.
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Affected products
- Sparxsystems Enterprise Architect: from 16.1.1627, before 17.1.1714 (fixed in 17.1.1714)
Published 2026-04-16. Last modified 2026-10-07.