Home
MEDIUM: 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/S:P/AU:Y/V:C/RE:MDefault status
unknown
16.1.1627
affected
17.1.1714
unaffected
Description
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Problem types
CWE-522: Insufficiently Protected Credentials
Product status
16.1.1627
17.1.1714
Credits
Pasi Orovuo, Solita Oy
Henri Hämäläinen, Solita Oy
Samu Ahvenainen, Solita Oy
References
sparxsystems.com/products/ea/17.1/history.html