# Botnet exploitation of NXRM up to 3.14.0

**URL:** <https://community.sonatype.com/t/botnet-exploitation-of-nxrm-up-to-3-14-0/1993>\
**Category:** Sonatype Nexus Repository\
**Created:** [June 13, 2019, 3:24pm UTC](https://community.sonatype.com/t/botnet-exploitation-of-nxrm-up-to-3-14-0/1993 "2019-06-13T15:24:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mprescott](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/mprescott/32/178_2.png) [@mprescott](https://community.sonatype.com/u/mprescott)\
**Post date:** [June 13, 2019, 3:24pm UTC](https://community.sonatype.com/t/botnet-exploitation-of-nxrm-up-to-3-14-0/1993/1 "2019-06-13T15:24:57Z")

</div>

**Affected Versions** : Nexus Repository Manager 3.x OSS/Pro versions up to and including 3.14.0

**Fixed in Version** : Nexus Repository Manager OSS/Pro version 3.15.0

Sonatype has become aware of **botnet exploitation** of a previously announced security vulnerability, and recommends immediate upgrade of affected NXRM 3.x instances. (NXRM 2.x instances are not affected.)

Sonatype has **expanded the range of affected versions** to include older versions of NXRM prior to 3.6.2.

Information about the vulnerability was previously published in the Sonatype security knowledge base at:

[https://support.sonatype.com/hc/en-us/articles/360017310793-CVE-2019-7238-Nexus-Repository-Manager-3-Missing-Access-Controls-and-Remote-Code-Execution-February-5th-2019](https://support.sonatype.com/hc/en-us/articles/360017310793-CVE-2019-7238-Nexus-Repository-Manager-3-Missing-Access-Controls-and-Remote-Code-Execution-February-5th-2019)

Instances of Repository Manager that are publicly accessible on the internet are at extreme risk of exploitation. Non-publicly accessible instances are at lower risk, but still pose a risk of insider threat.

We recommend **immediate upgrade of vulnerable versions** of Nexus Repository Manager to the latest version, currently 3.16.2.

---

<div class="post-metadata">

**Author:** ![nickcook](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/nickcook/32/399_2.png) [@nickcook](https://community.sonatype.com/u/nickcook)\
**Post date:** [June 13, 2019, 4:44pm UTC](https://community.sonatype.com/t/botnet-exploitation-of-nxrm-up-to-3-14-0/1993/2 "2019-06-13T16:44:21Z")

</div>


