Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Sonatype

Sonatype

enriched
Application Security (ASPM)Container Security

Represented by Carahsoft ↗

sonatype.com ↗ · required email domain for this vendor's users

Do you work at Sonatype?

This profile was built from public sources and hasn't been claimed yet. Claiming it lets you correct what's wrong and add details only you can confirm — and marks that information as vendor-verified for buyers.

Free, and it does not affect ranking, placement, or comparison results. The first person verified on Sonatype's email domain becomes the profile admin.

Claim this profileAlready have an account?

Trust profileHow to read thisFive separate questions a buyer actually asks, each answered with its own evidence and a link to the source. There is deliberately no overall score: a single number invites comparison it cannot support, and would mostly reflect how much of Sonatype we have managed to scan rather than anything about the vendor.

Not checked means we have not looked yet, and is never counted against a vendor. Limited means we did look, but found only one line of evidence — enough to report, not enough to corroborate.

checked 6 of 16 signals
  • Limited

    Independently verified

    Has anyone other than the vendor confirmed this?

    checked 3 of 4

    Nothing here has been confirmed by an independent third party yet.

    • No third-party certifications found
    • Profile not claimed by the vendor
  • Limited

    Operating durability

    Is this a real, durable business?

    checked 2 of 4

    How long this vendor has been operating, and who stands behind them.

    • Headquarters location not disclosed on their site
  • Mixed

    Behaviour under stress

    What do they do when something goes wrong?

    checked 1 of 3

    What their public record shows about handling vulnerabilities and outages.

    • 54 published CVE(s) — a public disclosure record exists
    • 3 rated critical
  • Not checked

    Disclosure posture

    Do they tell you the awkward things unprompted?

    checked 0 of 3

    We have not checked what this vendor discloses publicly yet.

    Nothing checked here yet — this is not a mark against Sonatype.

  • Not checked

    Momentum

    Are they still shipping, or coasting?

    checked 0 of 2

    We have not tracked this vendor's release activity yet.

    Nothing checked here yet — this is not a mark against Sonatype.

Data coverage: 15/100What this measures (and doesn't)

Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.

Verification depth0/100
Security signal0/100
Buyer feedbackno data yet (0 reviews so far)
Profile completeness25/100
claim · HQ · materials · screenshots · integrations · certifications · security check

The platform admin controls the formula's weights.

Data coverage profileHow to read thisThe same four components behind the data coverage score above, shaped instead of listed — a vendor strong on verification but thin on buyer feedback looks visibly different from one that's the other way around. Security and feedback plot at the neutral midpoint (50) when there's no data yet (no products tracked, no reviews), matching how the actual score itself treats missing data — not a guess either way.

VerificationSecurityFeedbackCompletenessThis vendor — Verification: 0This vendor — Security: 0This vendor — Feedback: no data yetThis vendor — Completeness: 25

IntegrationsUI-12 — integration graphDetected from this vendor's own published integration/partner pages by the enrichment loop — each entry links the exact page it was found on. Directional: "integrates with" is claimed by this vendor; "integrated by" is claimed by the other vendor's site. Coverage grows as the scan progresses.

9 detected

Integrates with: Embed Security ↗, Microsoft ↗, Shift Security ↗

Integrated by: Aqua Security, CloudDefense.AI, Cloudsmith, Konvu, Mend, Seemplicity

Buyer reviewsUI-14 — verified-buyer reviewsWritten only by domain-verified buyers at other companies, attributed to their company domain (never their identity), and moderated. Buyer-sourced opinion, clearly separate from the neutral catalog facts above — and never an input to search or comparison ordering.

verified buyers only

No buyer reviews yet.

Reputation ratingUI-20 — anonymous ratingA single anonymous 5-star signal from buyers, resellers, and analysts who've engaged with this vendor — separate from the domain-attributed reviews above. No rater identity is ever shown, not even at company level.

anonymous

No ratings in this window yet.

External ratingsUI-22 — third-party ratingsAggregate rating and review count pulled directly from the source site's own published data — never the review text itself, which belongs to that site. Links go to the real page so you can read the actual reviews there.

via third-party review sites
PeerSpot: 4.2/5 (48 reviews) ↗

Container security platform for vulnerability scanning and policy enforcement AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →

Product screenshots (3)

from their products
Sonatype SBOM ManagerautoSonatype LifecycleautoSonatype Container Security Solutionsauto

CVE severity over timeUI-24 — CVE severity timelineEvery known CVE with a disclosure date and severity, plotted by when it was published — lets you see whether disclosures are trending toward more or less severe, not just a raw count. Same NVD-sourced, name-matched data as the list below.

LOWMEDIUMHIGHCRITICAL2015201620172018201920202021202220232024CVE-2024-5764 · MEDIUM 6.5 · 2024-10-23CVE-2024-4956 · HIGH 7.5 · 2024-05-16CVE-2024-1142 · MEDIUM 5.4 · 2024-03-21CVE-2022-27907 · MEDIUM 4.3 · 2022-03-30CVE-2021-43961 · MEDIUM 4.3 · 2022-03-18CVE-2021-43293 · MEDIUM 4.3 · 2021-11-04CVE-2021-42568 · MEDIUM 4.3 · 2021-11-02CVE-2021-40143 · HIGH 8.2 · 2021-09-08CVE-2021-37152 · MEDIUM 5.4 · 2021-08-10CVE-2021-34553 · MEDIUM 4.3 · 2021-06-18CVE-2021-30635 · MEDIUM 5.3 · 2021-04-27CVE-2021-29158 · MEDIUM 4.9 · 2021-04-24CVE-2020-29436 · MEDIUM 6.5 · 2020-12-17CVE-2020-15012 · HIGH 8.6 · 2020-10-13CVE-2020-24622 · MEDIUM 4.9 · 2020-08-25CVE-2020-15868 · HIGH 7.5 · 2020-08-13CVE-2020-15871 · HIGH 8.8 · 2020-08-01CVE-2020-15870 · MEDIUM 6.1 · 2020-08-01CVE-2020-15869 · MEDIUM 5.4 · 2020-08-01CVE-2020-11415 · MEDIUM 4.9 · 2020-04-27CVE-2020-11753 · HIGH 8.8 · 2020-04-20CVE-2020-11444 · HIGH 8.8 · 2020-04-02CVE-2020-10204 · HIGH 7.2 · 2020-04-01CVE-2020-10203 · MEDIUM 4.8 · 2020-04-01CVE-2020-10199 · HIGH 8.8 · 2020-04-01CVE-2019-16530 · HIGH 7.2 · 2019-10-21CVE-2019-15893 · HIGH 7.2 · 2019-10-16CVE-2019-9630 · HIGH 7.5 · 2019-07-08CVE-2019-9629 · CRITICAL 9.8 · 2019-07-08CVE-2019-11629 · MEDIUM 6.1 · 2019-05-07CVE-2019-7238 · CRITICAL 9.8 · 2019-03-21CVE-2018-16621 · HIGH 7.2 · 2018-11-16CVE-2018-16620 · HIGH 7.5 · 2018-11-16CVE-2018-16619 · MEDIUM 6.1 · 2018-11-16CVE-2018-12100 · MEDIUM 4.8 · 2018-06-11CVE-2018-5307 · MEDIUM 6.1 · 2018-02-10CVE-2018-5306 · MEDIUM 6.1 · 2018-02-10CVE-2017-17717 · CRITICAL 9.8 · 2017-12-17CVE-2014-9389 · HIGH 7.5 · 2015-01-06CVE-2014-2034 · HIGH 7.5 · 2014-04-01CVE-2014-0792 · HIGH 7.5 · 2014-01-18

Known CVEs (54)About this listSourced from the public NVD database, matched by vendor name. This is a name-based match, not exact version tracking — always check the linked NVD record for affected versions before drawing conclusions. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-11403 ↗2026

    A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-…

  • CVE-2026-10741 ↗2026

    Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstre…

  • CVE-2026-10748 ↗2026

    An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repo…

  • CVE-2026-3329 ↗2026

    A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

  • CVE-2026-7308 ↗2026

    An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via t…

  • CVE-2026-3048 ↗2026

    An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections w…

  • CVE-2026-5189 ↗2026

    CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access …

  • CVE-2026-3438 ↗2026

    A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victi…

  • CVE-2026-3199 ↗2026

    A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, …

  • CVE-2026-0600 ↗2026

    Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access u…

  • CVE-2025-9868 ↗2025

    Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository crede…

  • CVE-2024-5082 ↗2024

    A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

  • CVE-2024-5083 ↗2024

    A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

  • CVE-2024-5764 ↗MEDIUM 6.52024

    Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (S…

  • CVE-2024-4956 ↗HIGH 7.52024

    Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.

  • CVE-2024-1142 ↗MEDIUM 5.42024

    Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 fixes this issue.

  • CVE-2022-27907 ↗MEDIUM 4.32022

    Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.

  • CVE-2021-43961 ↗MEDIUM 4.32022

    Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.

  • CVE-2021-43293 ↗MEDIUM 4.32021

    Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).

  • CVE-2021-42568 ↗MEDIUM 4.32021

    Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.

  • …and 34 more

Competitors (12)

full alternatives comparison →
AcunetixAdaCoreaDolus TechnologyAdroniteAnchoreCheckmarxCloudMatosCycodeMendQwietSec1SOOS

Products (3)

Application Security (ASPM)

2
  • Sonatype LifecycleAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Automated SCA tool for open source dependency management and vulnerability remediation
  • Sonatype SBOM ManagerAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Automates SBOM ingestion, monitoring, and compliance management for software

Container Security

1
  • Sonatype Container Security SolutionsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Container security platform for vulnerability scanning and policy enforcement