Executive brief
Sparx Systems Pro Cloud Server, a platform used to host and share Enterprise Architect models, contains a security flaw that allows unauthorized individuals to view sensitive system information. Specifically, an unauthenticated attacker can retrieve the database password in plain text under certain conditions. This could lead to a full compromise of the underlying database, resulting in the theft or modification of proprietary business models and sensitive organizational data.
Technical details
A vulnerability in Sparx Systems Pro Cloud Server (specifically identified in version 6.0.163) involves the exposure of sensitive system information and private personal information. The flaw allows an unauthenticated, remote attacker to retrieve the database password in plaintext under certain configurations. This is classified under CWE-359 (Exposure of Private Personal Information) and CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). An attacker with network access to the server can exploit this to gain credentials for the backend database, leading to unauthorized data access or modification. Users are advised to review the Sparx Systems release notes for version 6.1 for patching information.
Affected products
- Sparx Systems Pro Cloud Server 6.0.163 and earlier
Timeline
- 2026-04-17: disclosed
- 2026-04-17: advisory