HTTP: Sonatype Nexus Repository Manager CVE-2019-7238 Expression Language Injection

This signature detects attempts to exploit a known vulnerability against Sonatype Nexus Repository Manager.A successful attack can lead to arbitrary code execution.

Extended Description

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

Affected Products

Sonatype nexus

Short Name
HTTP:MISC:SONATYPE-REPO-CMDINJ
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2019-7238 Expression Injection Language Manager Nexus Repository Sonatype
Release Date
03/13/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3693
False Positive
Unknown
Vendors

Sonatype

CVSS Score

7.5

Found a potential security threat?