CVE-2025-15624
Analyzed
Analyzed - Analysis Complete
Plaintext Password Storage in Sparx Pro Cloud Server Risks Credential Exposure
Publication date: 2026-04-17
Last updated on: 2026-06-02
Assigner: National Cyber Security Centre Finland
Description
Description
Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.Β
In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sparxsystems | pro_cloud_server | 6.0.163 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-256 | The product stores a password in plaintext within resources such as memory or files. |