logo

Vulnerabilities in Sparx Systems products

ID: 3b09acc2-0fd1-5272-b3f5-12f6ae63b09e

STIX ID: report--3b09acc2-0fd1-5272-b3f5-12f6ae63b09e

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: CERT Polska

...
...

CERT Polska published a coordinated disclosure for five critical vulnerabilities in Sparx Systems products (Pro Cloud Server and Enterprise Architect) including broken access control and SQL execution as low-privileged users, an authentication bypass allowing unauthenticated SQL execution, client-side authentication weaknesses enabling impersonation, a race condition that can lead to remote code execution by creating and executing a malicious PHP file, and a malformed-SQL-induced denial-of-service. Confirmed vulnerable versions include Pro Cloud Server ≤ 6.1 (build 167) and Enterprise Architect ≤ 17.1; the vendor was notified and credited the reporter.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.