CVE-2025-15623
🟡 Monitoruj
Ujawnienie hasła do bazy danych w Sparx Pro Cloud Server umożliwia nieautoryzowanym użytkownikom dostęp do danych.
CVSS
7.5
EPSS
0.3%
Exploit
none
Vendor
sparxsystems
Opis źródłowy (NVD)
Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-04-17 09:16:04 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 09:10:00 UTC |
Referencje
- https://sparxsystems.com/products/procloudserver/6.1/history.html (db4dfee8-a97e-4877-bfae-eba6d14a2166) [Release Notes]