VYPR
Critical severity9.8NVD Advisory· Published Dec 2, 2019· Updated Jun 17, 2026

CVE-2019-15631

CVE-2019-15631

Description

Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.

Affected products

7
  • cpe:2.3:a:mulesoft:api_gateway:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mulesoft:api_gateway:*:*:*:*:*:*:*:*range: >=2.0.0,<=2.2.12
    • (no CPE)range: <October 31, 2019
  • cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:*:community:*+ 1 more
    • cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:*:community:*range: >=3.0.0,<=3.9.3
    • cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:enterprise:*:*range: >=3.0.0,<=3.9.3
  • Range: <October 31, 2019
  • MuleSoft/Mule API Gateway 2.xv5
    Range: released before October 31, 2019
  • MuleSoft/Mule CE/EE 3.xv5
    Range: released before October 31, 2019

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.