CRITICAL🇵🇱 Wersja polska

CVE-2025-15623

CVSS 9.3v4.0pub. 2026-04-17upd. 2026-06-02

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations

🤖 AI Analysis
How it works

The vulnerability encompasses two classes of errors: disclosure of private personal data to unauthorized entities (CWE-359) and exposure of sensitive system information outside the permitted control zone (CWE-497). Under specific conditions, the application exposes the database password in plaintext form without verifying the identity of the requester. An attacker can remotely, without logging in, obtain access to this data over the network.

Impact

An attacker can obtain database credentials, enabling unauthorized access to its resources, reading, modification, or exfiltration of data stored in the system.

Mitigation & patch

Apply patches available from the vendor according to the references: https://sparxsystems.com/products/procloudserver/6.1/history.html

Who is affected

Sparx Systems Pty Ltd. Sparx Pro Cloud Server — specific versions indicated in the vendor references (release history available at the reference address)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:C/RE:M/U:Red
  • Sparxsystems Pro Cloud Server

    APP
    Sparxsystems
    6.0.163
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-42097CRITICAL9.3PL ✓same product

Sparx Pro Cloud Server — SQL injection bez uwierzytelnienia przez pominięcie parametru

CVE-2025-15624CRITICAL9.3PL ✓same product

Plaintext Storage haseł w Sparx Pro Cloud Server z OpenID

CVE-2025-15625CRITICAL9.5PL ✓same product

SQL Injection w Sparx Pro Cloud Server — nieautoryzowany dostęp do bazy danych

CVE-2026-42096HIGH8.7same product

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to l...

CVE-2026-42099HIGH7.7same product

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. T...