Remote Code Execution Vulnerability in Sonatype Nexus Repository Manager and IQ Server
CVE-2019-16530

7.2HIGH

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
21 October 2019

What is CVE-2019-16530?

The Sonatype Nexus Repository Manager and IQ Server expose a critical vulnerability that allows remote code execution. Specific versions prior to Nexus Repository Manager 2.14.15 and 3.19, as well as IQ Server before 72, are impacted. Malicious actors can exploit this flaw to execute arbitrary code on affected systems, posing significant risks to the integrity and security of data managed by these products.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.