Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Sonatype/
  3. Sonatype SBOM Manager

Sonatype SBOM Manager

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 56 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Automates SBOM ingestion, monitoring, and compliance management for software

by Sonatype · sonatype.com · source ↗

Screenshots

1
Sonatype SBOM Manager — screenshotauto

Known CVEs (56)2 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-17600 ↗new2026

    Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password change…

  • CVE-2026-17598 ↗new2026

    Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account …

  • CVE-2026-11403 ↗2026

    A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-…

  • CVE-2026-10741 ↗2026

    Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstre…

  • CVE-2026-10748 ↗2026

    An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repo…

  • CVE-2026-3329 ↗2026

    A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

  • CVE-2026-7308 ↗2026

    An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via t…

  • CVE-2026-3048 ↗2026

    An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections w…

  • CVE-2026-5189 ↗2026

    CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access …

  • CVE-2026-3438 ↗2026

    A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victi…

  • CVE-2026-3199 ↗2026

    A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, …

  • CVE-2026-0600 ↗2026

    Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access u…

  • CVE-2025-9868 ↗2025

    Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository crede…

  • CVE-2024-5082 ↗2024

    A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

  • CVE-2024-5083 ↗2024

    A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

  • CVE-2024-5764 ↗MEDIUM 6.52024

    Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (S…

  • CVE-2024-4956 ↗HIGH 7.52024

    Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.

  • CVE-2024-1142 ↗MEDIUM 5.42024

    Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 fixes this issue.

  • CVE-2022-27907 ↗MEDIUM 4.32022

    Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.

  • CVE-2021-43961 ↗MEDIUM 4.32022

    Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.

  • …and 36 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Application Security (ASPM) products

see all →
  • AI SAST · Arnica
  • Acunetix Web Application & API Security · Acunetix
  • Adronite · Adronite
  • Almanax · Almanax
  • Amplify Security Fix Your Code · Amplify Security
  • Anchore Anchore Enterprise · Anchore
  • Apiiro AI SAST · Apiiro
  • Apiiro ASPM Platform · Apiiro