PT-2019-14688 · Sonatype · Sonatype Iq Server+2

Published

2019-10-21

·

Updated

2022-05-24

·

CVE-2019-16530

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sonatype Nexus Repository Manager versions 2.x through 2.14.14 Sonatype Nexus Repository Manager versions 3.x through 3.18 Sonatype IQ Server versions prior to 72
Description The issue allows for remote code execution.
Recommendations For Sonatype Nexus Repository Manager versions 2.x through 2.14.14, update to version 2.14.15 or later. For Sonatype Nexus Repository Manager versions 3.x through 3.18, update to version 3.19 or later. For Sonatype IQ Server versions prior to 72, update to version 72 or later.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16530
GHSA-HMJV-PX3J-933C

Affected Products

Nexus Repository Manager
Sonatype Iq Server
Sonatype Nexus Repository Manager