RULE(RULE ID:331248)

Rule General Information
Release Date: 2020-10-28
Rule Name: Sonatype Nexus Repository Manager ConstraintViolationFactory Code Execution Vulnerability (CVE-2020-10199)
Severity:
CVE ID:
Rule Protection Details
Description: Sonatype Nexus Repository Manager (NXRM) is a Maven warehouse manager from Sonatype in the United States. Sonatype Nexus Repository Manager before 3.21.2 There is a security breach. Attackers can use this vulnerability to execute arbitrary code with malicious requests.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux
Reference: http://packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.html
https://support.sonatype.com/hc/en-us/articles/360044882533
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://support.sonatype.com/hc/en-us/articles/360044882533-CVE-2020-10199-Nexus-Repository-Manager-3-Remote-Code-Execution-2020-03-31