CVE-2019-7238

CRITICAL KEV NUCLEI

Sonatype Nexus Repository Manager <3.15.0 - Privilege Escalation

Title source: llm

Description

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

Exploits (7)

nomisec WORKING POC 153 stars
by mpgn · remote
https://github.com/mpgn/CVE-2019-7238
nomisec WORKING POC 85 stars
by jas502n · remote
https://github.com/jas502n/CVE-2019-7238
nomisec WORKING POC 39 stars
by verctor · remote
https://github.com/verctor/nexus_rce_CVE-2019-7238
nomisec WORKING POC 25 stars
by magicming200 · poc
https://github.com/magicming200/CVE-2019-7238_Nexus_RCE_Tool
github NO CODE 3 stars
by HxDDD · poc
https://github.com/HxDDD/CVE-PoC/tree/main/Nexus/CVE-2019-7238
nomisec WRITEUP 2 stars
by DannyRavi · remote
https://github.com/DannyRavi/nmap-scripts
nomisec WORKING POC 1 stars
by smallpiggy · remote
https://github.com/smallpiggy/CVE-2019-7238

Nuclei Templates (1)

Sonatype Nexus Repository Manager <3.15.0 - Remote Code Execution
CRITICALby pikpikcu
FOFA: title="nexus repository manager"

Scores

CVSS v3 9.8
EPSS 0.9438
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2021-12-10
VulnCheck KEV 2019-06-12
InTheWild.io 2021-04-08
ENISA EUVD EUVD-2019-16782

Classification

Status published

Affected Products (1)

sonatype/nexus_repository_manager < 3.15.0

Timeline

Published Mar 21, 2019
KEV Added Dec 10, 2021
Tracked Since Feb 18, 2026