CVE detail
CVE-2020-15012 — CVE-2020-15012
Published 2020-10-12 · Modified 2026-06-17 · Vendor sonatype · Product nexus_repository_manager · Source nvd
HIGH
severity
CVSS-derived band
0.0259
EPSS probability
exploitation probability, 30d
84.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References