Junglewise Threat Intelligence

CVE-2025-15624: Sparx Systems Pro Cloud Server plaintext password storage in OpenID setup

CVE-2025-15624 · Severity: high · CVSS 7.5 · Published 2026-04-17

Technologies: Sparx Systems Pro Cloud Server. Vendors: Sparx Systems.

Executive brief

Sparx Pro Cloud Server, a platform used to host and share Enterprise Architect models, contains a security flaw in how it handles user credentials. When configured to use OpenID for logins, the system incorrectly generates and stores local user passwords in an unencrypted, readable format. This could allow an unauthorized person with access to the server's storage to see and use these passwords, potentially compromising user accounts and sensitive project data.

Technical details

A Plaintext Storage of a Password vulnerability (CWE-256) exists in Sparx Pro Cloud Server. When the system is configured to use OpenID as the primary authentication method for Sparx EA, the Pro Cloud Server component generates local passwords for users and stores them in plaintext rather than using a secure hashing algorithm. An attacker with access to the underlying data store or configuration files could retrieve these credentials. The vulnerability is present in version 6.0.163 and was addressed in subsequent releases; users are advised to consult the Sparx Systems release history for patch details.

Affected products

  • Sparx Systems Pty Ltd. Pro Cloud Server 6.0.163 and earlier

Timeline

  • 2026-04-17: advisory: Initial disclosure by National Cyber Security Centre Finland
  • 2026-06-02: other: NVD analysis and CPE information added

References

Related threats