EXPOSURES › CVE-2019-7238
CVE-2019-7238
HIGH ⌖ ON CISA KEV · EXPLOITEDSonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability allowing remote code execution.
This vulnerability allows attackers to execute arbitrary code remotely, compromising the integrity of software repositories used by DIB organizations. It is actively exploited in the wild, indicating a high risk of compromise if unpatched. DIBs must ensure their Nexus installations are updated to version 3.15.0 or later and monitor for exploitation attempts.
Shame score — The vulnerability is actively exploited in the wild and allows remote code execution, representing a severe and avoidable risk for organizations relying on this software.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.