Back to Database
Status published
Critical
CVE-2025-15625
Unauthenticated execution of arbitrary SQL queries in Sparx Pro Cloud Server
Vulnerability Description
Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15625
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Pasi Orovuo, Solita Oy
- Henri Hämäläinen, Solita Oy
- Samu Ahvenainen, Solita Oy
More from Sparx Systems Pty Ltd.
View All →CVE-2025-15624
Plaintext Storage of a Password in Sparx Pro Cloud Server.
Critical
9.3
CVE-2025-15623
Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
Critical
9.3
CVE-2025-15622
Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret
Medium
6.2
CVE-2025-15621
Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Medium
5.7
Affected Vendor
Sparx Systems Pty Ltd.
View all reports →Affected Software
Sparx Pro Cloud Server
Vulnerable Versions:
6.0.163
Timeline
Official Publish:
April 17th, 2026
Last Modified:
April 17th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
MITRE ATT&CK TTPs
T1190
Exploit Public-Facing Application
Initial Access
T1059
Command and Scripting Interpreter
Execution
T1213.006
Databases
Collection
T1485
Data Destruction
Impact
T1213
Data from Information Repositories
Collection
T1005
Data from Local System
Collection
T1552
Unsecured Credentials
Credential Access
T1041
Exfiltration Over C2 Channel
Exfiltration