Vulnerability record · CVE-2019-7238 · published 21 March 2019
CVE-2019-7238: Sonatype Nexus Repository Manager incorrect access control allows RCE
Sonatype · Nexus Repository Manager
Sonatype Nexus Repository Manager before 3.15.0 has incorrect access control, and the vendor advisory describes it as missing access controls leading to remote code execution. The flaw is remotely reachable without authentication, so an unpatched repository server is exposed to full compromise. It is listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild should be assumed.
Description
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, confirmed exploitation in CISA KEV, and very high EPSS probability.
What it is
Sonatype Nexus Repository Manager before 3.15.0 has incorrect access control, and the vendor advisory describes it as missing access controls leading to remote code execution. The flaw is remotely reachable without authentication, so an unpatched repository server is exposed to full compromise. It is listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild should be assumed.
Impact
An unauthenticated attacker can bypass access controls and execute code on the Nexus Repository Manager host, gaining full control of the server and any data or credentials it holds.
Attack surface
Reachable over the network via the Nexus Repository Manager service; the CVSS vector shows no privileges and no user interaction required. No further detail on the specific endpoint is given in the record.
Exploitation
CISA KEV lists it as exploited, with a required action to apply vendor updates, and EPSS is 0.77146 (99.5th percentile), indicating high likelihood of exploitation activity. No ransomware campaign use is documented.
What to do
- Upgrade Nexus Repository Manager to 3.15.0 or later per the vendor advisory.
- If immediate patching is not possible, restrict network access to the Nexus service to trusted hosts only.
- Remove or disable anonymous access where it is not required.
- Monitor vendor advisories for any follow-up guidance on this CVE.
Detection
- Review Nexus Repository Manager logs for unexpected or anomalous requests, especially from untrusted source IPs.
- Alert on unexpected child processes or command execution spawned by the Nexus service.
- Audit network exposure of Nexus instances and flag any reachable from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-7238 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-7238 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7238), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.