PatchSiren

Sparx Systems Pty Ltd. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Sparx Systems Pty Ltd. CVE published 2026-04-17

CVE-2025-15622

The CVE-2025-15622 vulnerability in Sparx Enterprise Architect exposes OAuth2 client secrets due to insufficient protection. This medium-severity issue, with a CVSS score of 6.2, allows client-side exposure of plaintext OAuth2 client secrets, which are then used for token exchange in the OpenID authentication flow. Defenders should assess exposure, verify OAuth2 client secret handling, and review OpenID c [truncated]

MEDIUM Sparx Systems Pty Ltd. CVE published 2026-04-16

CVE-2025-15621

The CVE record for CVE-2025-15621 was published on 2026-04-16T13:16:43.423Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Sparx Systems Pty Ltd. Sparx Enterprise Architect, specifically in its handling of OAuth2 credentials during OpenID authentication, leading to insufficiently protected credentials. Security teams and administrators should review t [truncated]