Sparx Systems Sparx Enterprise Architect
cpe:2.3:a:sparxsystems:enterprise_architect:*:*:*:*:*:*:*
- >= 17.0, < 17.1
A vulnerability in Sparx Systems Sparx Enterprise Architect allows the desktop client to access plaintext OAuth2 client secrets. This secret is then used to obtain access and ID tokens during the OpenID authentication process. The issue arises from inadequate protection of credentials, exposing sensitive information that can be exploited in the authentication flow.
Exploitation of this vulnerability leads to unauthorized access tokens being obtained, which could allow for impersonation or access to resources on behalf of the user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.