In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 17 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sparxsystems
Sparxsystems sparx Pro Cloud Server |
|
| Vendors & Products |
Sparxsystems
Sparxsystems sparx Pro Cloud Server |
Fri, 17 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext. | |
| Title | Plaintext Storage of a Password in Sparx Pro Cloud Server. | |
| Weaknesses | CWE-256 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC-FI
Published:
Updated: 2026-04-17T11:58:38.118Z
Reserved: 2026-04-09T08:02:32.647Z
Link: CVE-2025-15624
Updated: 2026-04-17T11:58:30.673Z
Status : Awaiting Analysis
Published: 2026-04-17T09:16:04.723
Modified: 2026-04-17T15:13:15.930
Link: CVE-2025-15624
No data.
OpenCVE Enrichment
Updated: 2026-04-17T20:35:24Z