CVE-2025-15621
Severity CVSS v4.0:
MEDIUM
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
16/04/2026
Last modified:
17/04/2026
Description
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication



