Critical severity9.8NVD Advisory· Published Dec 2, 2019· Updated Jun 17, 2026
CVE-2019-15631
CVE-2019-15631
Description
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
Affected products
7cpe:2.3:a:mulesoft:api_gateway:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mulesoft:api_gateway:*:*:*:*:*:*:*:*range: >=2.0.0,<=2.2.12
- (no CPE)range: <October 31, 2019
cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:*:community:*+ 1 more
- cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:*:community:*range: >=3.0.0,<=3.9.3
- cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:enterprise:*:*range: >=3.0.0,<=3.9.3
- Range: <October 31, 2019
- MuleSoft/Mule API Gateway 2.xv5Range: released before October 31, 2019
- MuleSoft/Mule CE/EE 3.xv5Range: released before October 31, 2019
Patches
Vulnerability mechanics
References
1- help.salesforce.com/articleViewnvdThird Party Advisory
News mentions
0No linked articles in our index yet.