Security Advisory

CVE-2025-15624

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-17 08:38:36
Last updated 2026-04-17 11:58:38
Assigner NCSC-FI
State PUBLISHED

Description

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext.