Listen to this Post
CVE-2025-15621 is a medium-severity vulnerability identified in Sparx Systems Pty Ltd.’s Sparx Enterprise Architect, a commercial closed-source UML modeling tool widely used for software architecture and system design modeling. The vulnerability stems from an insufficiently protected credentials flaw (CWE-522) in the OAuth2 client implementation during the OpenID authentication flow.
In a properly implemented OpenID Connect authentication flow, the OAuth2 client must verify that the credentials it sends—such as authorization codes, access tokens, and ID tokens—are being delivered to the intended recipient. This verification typically involves validating the redirect URI, checking the client ID against the authorized party, and ensuring that token exchange requests originate from the legitimate client. The OAuth2 client in Sparx Enterprise Architect, however, fails to perform this critical receiver verification step.
The vulnerability manifests when the Enterprise Architect client initiates an OpenID authentication session. The client transmits OAuth2 credentials without confirming that the receiving endpoint is the legitimate authentication server or authorized relying party. This omission creates a scenario where credentials could be redirected to an unintended recipient through various attack vectors.
An attacker with local access and low privileges could potentially intercept or receive these OAuth2 credentials during the authentication handshake. The attack requires specific preconditions to be present and relies on passive user interaction, limiting the immediate risk but still posing a significant confidentiality threat. The credentials obtained could then be used to impersonate legitimate users and gain unauthorized access to accounts and systems that rely on the compromised credentials.
The vulnerability was discovered and reported by security researchers Pasi Orovuo, Henri Hämäläinen, and Samu Ahvenainen from Solita Oy. The affected versions include Sparx Enterprise Architect up to version 16.1.1627. The issue has been addressed in version 17.1.1714, where the vendor implemented additional receiver verification mechanisms in the OAuth2 authentication flow.
The CVSS v4.0 base score for this vulnerability is 5.7 (Medium), with the vector string CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N. The attack vector is local (AV:L), requiring the attacker to have local access to the target system. The attack complexity is high (AC:H), meaning exploitation depends on constrained or hard-to-reproduce conditions. Additional attack requirements (AT:P) must be present, and low privileges (PR:L) are sufficient for the attacker. User interaction is required (UI:P), as a user must participate in the authentication process. The vulnerability has a high confidentiality impact (VC:H) on the vulnerable system and also affects subsequent systems with high confidentiality impact (SC:H).
DailyCVE Form:
Platform: Sparx Enterprise Architect
Version: 16.1.1627 and earlier
Vulnerability: OAuth2 receiver verification missing
Severity: Medium (CVSS 5.7)
Date: 2026-04-16
Prediction: Patch available in 17.1.1714
What Undercode Say:
Analytics & Detection Commands
Check installed version:
Windows Registry check reg query "HKLM\SOFTWARE\Sparx Systems\Enterprise Architect" /v Version
Check file version wmic product where "name like '%%Enterprise Architect%%'" get name,version
Monitor OAuth2 traffic for anomalies:
Monitor network connections to OAuth endpoints netstat -an | findstr :443
Capture OAuth2-related traffic (educational use only) tcpdump -i eth0 -n -v "port 443 and (host auth.example.com)"
Check for suspicious authentication logs:
Windows Security Event Log - failed logins Get-EventLog -LogName Security -InstanceId 4625 | Select-Object TimeGenerated, Message
Verify patch status:
Check if fix is applied (version check)
$version = (Get-Item "C:\Program Files\Sparx Systems\EA\EA.exe").VersionInfo.FileVersion
if ($version -ge "17.1.1714") { "Patched" } else { "Vulnerable" }
Exploit: (Educational Purposes!)
The exploitation of CVE-2025-15621 relies on the client’s failure to verify the receiver of OAuth2 credentials during OpenID authentication. In a practical attack scenario, an adversary with local access to the system could set up a malicious OAuth2 endpoint or manipulate the authentication flow to redirect credentials to an attacker-controlled receiver.
Conceptual attack flow:
- Attacker gains local access to a system running a vulnerable version of Sparx Enterprise Architect (≤16.1.1627).
- Attacker positions themselves to intercept or redirect OAuth2 traffic during OpenID authentication.
- When a user initiates OpenID authentication through the Enterprise Architect client, the client sends OAuth2 credentials without verifying the receiver’s identity.
- Credentials are transmitted to the attacker’s endpoint instead of the legitimate authentication server.
- Attacker captures the credentials and uses them to impersonate the legitimate user.
No public proof-of-concept exploit is currently available. The exploitation is considered difficult and requires specific preconditions to be present.
Protection:
- Upgrade to version 17.1.1714 or later – This is the primary mitigation, as the vendor has addressed the vulnerability by adding receiver verification in the OAuth2 authentication flow.
- Prioritize patching – Focus on systems running earlier versions of Enterprise Architect, particularly in environments where local user access is possible.
- Review authentication practices – Ensure users are connecting to legitimate authentication endpoints and reinforce authentication policies.
- Implement additional access controls – Deploy monitoring for suspicious authentication attempts and consider restricting local access to sensitive systems.
- Monitor for unusual activity – Regularly review authentication logs and network connections to OAuth endpoints for any anomalies.
Impact:
An attacker with local access and low privileges could potentially intercept or receive OAuth2 credentials during the OpenID authentication process. This could result in unauthorized access to user accounts and systems that rely on the compromised credentials. The vulnerability requires specific attack preconditions and relies on passive user interaction, limiting the immediate risk but still posing a confidentiality threat. The confidentiality impact is rated High (VC:H) for both the vulnerable system and subsequent systems (SC:H), while integrity impact is limited (VI:L, SI:L) and availability impact is none (VA:N, SA:N).
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

