CVE-2019-15588
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.
- Affected products
- Nexus Repository Manager
- Sonatype Nexus Repository Manager
- ≤ 2.14.14
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 5.6% (92th percentile)
- Weakness
- CWE-78, CWE-77
- NVD status
- Modified
- Published
- 2019-11-01
CVE-2019-15588 at NVD
5 known exploits for CVE-2019-15588
Proof-of-concept code and exploit modules indexed by Sploitus