Unauthenticated user can retrieve database password in plaintext in certain situations
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 17 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sparxsystems
Sparxsystems sparx Pro Cloud Server |
|
| Vendors & Products |
Sparxsystems
Sparxsystems sparx Pro Cloud Server |
Fri, 17 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations | |
| Title | Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user | |
| Weaknesses | CWE-359 CWE-497 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC-FI
Published:
Updated: 2026-04-17T12:19:21.714Z
Reserved: 2026-04-09T08:02:30.837Z
Link: CVE-2025-15623
Updated: 2026-04-17T12:19:13.648Z
Status : Awaiting Analysis
Published: 2026-04-17T09:16:04.593
Modified: 2026-04-17T15:13:15.930
Link: CVE-2025-15623
No data.
OpenCVE Enrichment
Updated: 2026-04-17T20:35:26Z