Sparx Systems Pro Cloud Server was assigned two high-severity vulnerabilities affecting authentication and database security. CVE-2025-15624 describes a plaintext password storage issue that occurs when OpenID is used as the primary authentication method for Sparx EA, causing Pro Cloud Server to generate local user passwords and store them in plaintext. The flaw is mapped to CWE-256 and was scored with a CVSS v4.0 vector indicating network exposure, low attack complexity, no privileges required, and high confidentiality and integrity impact.
A second issue, CVE-2025-15625, allows an unauthenticated attacker to execute arbitrary SQL queries against the Pro Cloud Server database in certain cases. The vulnerability is mapped to CWE-89 and CWE-200, and its CVSS v4.0 vector indicates remote exploitation without privileges or user interaction, though with high attack complexity. Both CVEs reference Sparx Systems Pro Cloud Server 6.1 history information, linking the disclosures to vendor-documented product changes and fixes.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
On April 17, 2026, new CVE entries were recorded for two Sparx Pro Cloud Server issues: CVE-2025-15624, involving plaintext storage of locally created passwords when OpenID is used as the primary authentication method, and CVE-2025-15625, involving unauthenticated execution of arbitrary SQL queries in certain cases. The CVEs were classified under CWE-256, CWE-89, and CWE-200 and referenced Sparx Systems Pro Cloud Server 6.1 history information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.