Vulnerabilities (CVE)

Filtered by vendor Sonatype Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-7238 1 Sonatype 1 Nexus 2020-08-24 7.5 HIGH 9.8 CRITICAL
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
CVE-2019-9629 1 Sonatype 1 Nexus Repository Manager 2020-08-24 7.5 HIGH 9.8 CRITICAL
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
CVE-2017-17717 1 Sonatype 1 Nexus Repository Manager 2018-01-04 10.0 HIGH 9.8 CRITICAL
Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.