Skip to content
COOEY

EXPOSURES › CVE-2019-7238

CVE-2019-7238

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-7238 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability allowing remote code execution.

This vulnerability allows attackers to execute arbitrary code remotely, compromising the integrity of software repositories used by DIB organizations. It is actively exploited in the wild, indicating a high risk of compromise if unpatched. DIBs must ensure their Nexus installations are updated to version 3.15.0 or later and monitor for exploitation attempts.

Shame score — The vulnerability is actively exploited in the wild and allows remote code execution, representing a severe and avoidable risk for organizations relying on this software.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.