RULE(RULE ID:321636)

Rule General Information
Release Date: 2019-03-20
Rule Name: Sonatype Nexus Repository Manager Expression Language Injection Vulnerability(CVE-2019-7238)
Severity:
CVE ID:
Rule Protection Details
Description: Nexus Repository Manager is a product, referred to as NXRM, which is a general-purpose package repository management service. On February 5, 2019, Sonatype released a security bulletin. In the Nexus Repository Manager 3, due to the lack of access control measures, unauthorized users can execute Java code on the server via a crafted request to achieve remote code execution.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference:
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.