RULE(RULE ID:330054)

Rule General Information
Release Date: 2020-04-20
Rule Name: Nexus Repository Manager Java EL Injection RCE Vulnerability (CVE-2020-10199)
Severity:
CVE ID:
Rule Protection Details
Description: Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.html
https://support.sonatype.com/hc/en-us/articles/360044882533
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://support.sonatype.com/hc/en-us/articles/360044882533-CVE-2020-10199-Nexus-Repository-Manager-3-Remote-Code-Execution-2020-03-31