VYPR

Nexus Iq Server

by Sonatype

CVEs (2)

  • CVE-2019-16530HigOct 21, 2019
    risk 0.47cvss 7.2epss 0.03

    Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.

  • CVE-2024-1142MedMar 21, 2024
    risk 0.35cvss 5.4epss 0.01

    Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 fixes this issue.