Cyber Resilience

CVE-2019-7238

Sonatype Nexus Repository Manager 3.0.0 – 3.15.0

CISA KEVActive ExploitationEUVD Exploited
Published
21 March 2019
Modified
06 November 2025
KEV Added
10 December 2021
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.77 99.5th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2019-7238 is a critical-severity an unspecified weakness vulnerability in Sonatype Nexus Repository Manager. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.5% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Sonatype Nexus Repository Manager versions prior to 3.15.0 contain an incorrect access control vulnerability that permits unauthorized interaction with repository functions. The flaw affects the core access control mechanisms of the widely deployed artifact repository server and carries a CVSS 3.1 base score of 9.8, reflecting network-accessible attack vectors that require no authentication or user interaction.

An unauthenticated remote attacker can exploit the missing controls to achieve remote code execution, resulting in complete compromise of confidentiality, integrity, and availability on the affected server. Because the vulnerability can be reached directly over the network, any exposed Nexus instance is potentially reachable by an attacker on the internet or within an internal network segment.

The official Sonatype advisory published on 5 February 2019 explicitly links the access-control deficiency to remote code execution and recommends upgrading to version 3.15.0 or later. The same issue appears in the CISA Known Exploited Vulnerabilities catalog, confirming that in-the-wild exploitation has been observed.

EU & UK References

Vulnerability Data

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

CWE(s)
KEV Date Added
10 December 2021

Related Threats

CVEs Like This One

CVE-2026-3329Same product: Sonatype Nexus Repository Manager
CVE-2026-10741Same product: Sonatype Nexus Repository Manager
CVE-2024-5764Same product: Sonatype Nexus Repository Manager
CVE-2020-10199Same vendor: Sonatypeboth on KEV

Affected Assets

sonatype
nexus repository manager
3.0.0 — 3.15.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References