{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-15623",
        "assignerOrgId": "db4dfee8-a97e-4877-bfae-eba6d14a2166",
        "state": "PUBLISHED",
        "assignerShortName": "NCSC-FI",
        "dateReserved": "2026-04-09T08:02:30.837Z",
        "datePublished": "2026-04-17T08:37:27.611Z",
        "dateUpdated": "2026-04-17T12:19:21.714Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "db4dfee8-a97e-4877-bfae-eba6d14a2166",
                "shortName": "NCSC-FI",
                "dateUpdated": "2026-04-17T08:37:27.611Z"
            },
            "title": "Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-359",
                            "description": "CWE-359: Exposure of Private Personal Information to an Unauthorized Actor",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-497",
                            "description": "CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Sparx Systems Pty Ltd.",
                    "product": "Sparx Pro Cloud Server",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "6.0.163"
                        }
                    ],
                    "defaultStatus": "unknown"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.\n\nUnauthenticated user can retrieve database password in plaintext in certain situations",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<div><span>Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.</span></div><p><span>Unauthenticated user can retrieve database password in plaintext in certain situations</span></p><p><br></p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://sparxsystems.com/products/procloudserver/6.1/history.html"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "LOW",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "LOW",
                        "vulnAvailabilityImpact": "NONE",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "PRESENT",
                        "Automatable": "YES",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "CONCENTRATED",
                        "vulnerabilityResponseEffort": "MODERATE",
                        "providerUrgency": "RED",
                        "version": "4.0",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 9.3,
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/S:P/AU:Y/V:C/RE:M/U:Red"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Pasi Orovuo, Solita Oy",
                    "type": "finder"
                },
                {
                    "lang": "en",
                    "value": "Henri Hämäläinen, Solita Oy",
                    "type": "finder"
                },
                {
                    "lang": "en",
                    "value": "Samu Ahvenainen, Solita Oy",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-04-17T12:00:21.330537Z",
                                "id": "CVE-2025-15623",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-04-17T12:19:21.714Z"
                }
            }
        ]
    }
}