CVE-2019-7238
Sonatype Nexus Repository Manager 3.0.0 – 3.15.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2019-7238 is a critical-severity an unspecified weakness vulnerability in Sonatype Nexus Repository Manager. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 0.5% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
Sonatype Nexus Repository Manager versions prior to 3.15.0 contain an incorrect access control vulnerability that permits unauthorized interaction with repository functions. The flaw affects the core access control mechanisms of the widely deployed artifact repository server and carries a CVSS 3.1 base score of 9.8, reflecting network-accessible attack vectors that require no authentication or user interaction.
An unauthenticated remote attacker can exploit the missing controls to achieve remote code execution, resulting in complete compromise of confidentiality, integrity, and availability on the affected server. Because the vulnerability can be reached directly over the network, any exposed Nexus instance is potentially reachable by an attacker on the internet or within an internal network segment.
The official Sonatype advisory published on 5 February 2019 explicitly links the access-control deficiency to remote code execution and recommends upgrading to version 3.15.0 or later. The same issue appears in the CISA Known Exploited Vulnerabilities catalog, confirming that in-the-wild exploitation has been observed.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2019-16782
Vulnerability Data
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
- CWE(s)
- KEV Date Added
- 10 December 2021
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.