Home

Description

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations

PUBLISHED Reserved 2026-04-09 | Published 2026-04-17 | Updated 2026-04-17 | Assigner NCSC-FI




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/S:P/AU:Y/V:C/RE:M/U:Red

Problem types

CWE-359: Exposure of Private Personal Information to an Unauthorized Actor

CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere

Product status

Default status
unknown

6.0.163
affected

Credits

Pasi Orovuo, Solita Oy finder

Henri Hämäläinen, Solita Oy finder

Samu Ahvenainen, Solita Oy finder

References

sparxsystems.com/products/procloudserver/6.1/history.html

cve.org (CVE-2025-15623)

nvd.nist.gov (CVE-2025-15623)

Download JSON