CVE-2019-16530: Malicious File Upload
Published Oct 21, 2019
·Updated
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Affected Software
3 affected components
Sonatype Nexus Iq Server<=72
Sonatype Nexus Repository Manager>=2.0.0<=2.14.14
Sonatype Nexus Repository Manager>=3.0.0<=3.18.1
Remediation
Patch Available
Event History
Oct 21, 2019
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16530?
CVE-2019-16530 is a vulnerability affecting Sonatype Nexus Repository Manager 2.x before 2.14.15, 3.x before 3.19, and IQ Server before 72, allowing remote code execution.
2
How severe is CVE-2019-16530?
CVE-2019-16530 has a severity keyword of critical with a CVSS score of 7.2.
3
How do I know if my system is affected by CVE-2019-16530?
If you are using Sonatype Nexus Repository Manager versions mentioned in the vulnerability description or IQ Server before version 72, your system may be affected.
4
What is the CWE associated with CVE-2019-16530?
CVE-2019-16530 is associated with CWE-434.
5
Where can I find more information about CVE-2019-16530?
You can find more information about CVE-2019-16530 on the Sonatype website or related security advisories.