---
id: CVE-2025-15621
title: Insufficiently Protected Credentials in Sparx Systems Pty Ltd
summary: >-
  Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx
  Enterprise Architect. Client does not verify the receiver of OAuth2
  credentials during OpenID authentication
severity: medium
cvss: 6
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-522
vendor: sparxsystems
product: enterprise_architect
affected:
  - 'enterprise_architect >= 16.1.1627, < 17.1.1714'
patched:
  - enterprise_architect 17.1.1714
published: '2026-04-16'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15621'
references:
  - url: 'https://sparxsystems.com/products/ea/17.1/history.html'
    label: db4dfee8-a97e-4877-bfae-eba6d14a2166
tags:
  - nvd
epss: 0.00106
epssPercentile: 0.01025
ingestedAt: '2026-08-22T01:24:50.996Z'
---

## Overview

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

## Affected

- `enterprise_architect >= 16.1.1627, < 17.1.1714`

## Remediation

Upgrade past the affected range:

- `enterprise_architect 17.1.1714`
