CRITICAL🇵🇱 Wersja polska

CVE-2025-15624

CVSS 9.3v4.0pub. 2026-04-17upd. 2026-06-02

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext.

🤖 AI Analysis
How it works

In a configuration where OpenID is the primary authentication method for Sparx EA via Pro Cloud Server, the application creates local users and generates passwords for them. The generated passwords are then stored in the data store in plaintext form, without applying hashing or encryption mechanisms. An attacker or unauthorized person with access to the database or server configuration files can read these passwords directly without the need to crack them.

Impact

An attacker with access to the server's file system or database can read passwords of all local user accounts in plaintext form, enabling account takeover and unauthorized access to the Sparx EA environment.

Mitigation & patch

Apply patches available from the vendor according to references — Sparx Pro Cloud Server 6.1 release history is available at https://sparxsystems.com/products/procloudserver/6.1/history.html. Until the update is applied, it is recommended to restrict access to configuration files and server database exclusively to authorized administrators and monitor access to these resources.

Who is affected

Sparx Pro Cloud Server — versions indicated in vendor references (release history available at: https://sparxsystems.com/products/procloudserver/6.1/history.html); the issue affects configurations with OpenID enabled as the primary authentication method.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:C/RE:M/U:Red
  • Sparxsystems Pro Cloud Server

    APP
    Sparxsystems
    6.0.163
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-42097CRITICAL9.3PL ✓same product

Sparx Pro Cloud Server — SQL injection bez uwierzytelnienia przez pominięcie parametru

CVE-2025-15623CRITICAL9.3PL ✓same product

Sparx Pro Cloud Server: ujawnienie hasła do bazy danych w plaintext

CVE-2025-15625CRITICAL9.5PL ✓same product

SQL Injection w Sparx Pro Cloud Server — nieautoryzowany dostęp do bazy danych

CVE-2026-42096HIGH8.7same product

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to l...

CVE-2026-42099HIGH7.7same product

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. T...