Home

Description

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext.

PUBLISHED Reserved 2026-04-09 | Published 2026-04-17 | Updated 2026-04-17 | Assigner NCSC-FI




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/S:P/AU:Y/V:C/RE:M/U:Red

Problem types

CWE-256: Plaintext Storage of a Password

Product status

Default status
unknown

6.0.163
affected

Credits

Pasi Orovuo, Solita Oy finder

Henri Hämäläinen, Solita Oy finder

Samu Ahvenainen, Solita Oy finder

References

sparxsystems.com/products/procloudserver/6.1/history.html

cve.org (CVE-2025-15624)

nvd.nist.gov (CVE-2025-15624)

Download JSON