« Volver al listado

CVE-2019-15631

Estado: ModificadaCrítica (9.8)—

Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-15631",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@salesforce.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@salesforce.com",
      "affectedData": [
        {
          "vendor": "MuleSoft",
          "product": "Mule CE/EE 3.x",
          "versions": [
            {
              "status": "affected",
              "version": "released before October 31, 2019"
            }
          ]
        },
        {
          "vendor": "MuleSoft",
          "product": "Mule API Gateway 2.x",
          "versions": [
            {
              "status": "affected",
              "version": "released before October 31, 2019"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-12-02T02:15:10.613",
  "references": [
    {
      "url": "https://help.salesforce.com/articleView?id=000351827&language=en_US&type=1&mode=1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@salesforce.com"
    },
    {
      "url": "https://help.salesforce.com/articleView?id=000351827&language=en_US&type=1&mode=1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de Ejecución de Código Remota en MuleSoft Mule CE/EE versiones 3.x y API Gateway versiones 2.x publicadas antes del 31 de octubre de 2019, permite a atacantes remotos ejecutar código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T02:20:47.013",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mulesoft:api_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC61DCD4-5624-473D-9325-14572EDCD561",
              "versionEndIncluding": "2.2.12",
              "versionStartIncluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:*:community:*",
              "vulnerable": true,
              "matchCriteriaId": "BD243CEB-4A42-4746-A9F3-C3214AEF600E",
              "versionEndIncluding": "3.9.3",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:enterprise:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C4FA5E7-A41D-4F59-81A5-21A047E9E7E8",
              "versionEndIncluding": "3.9.3",
              "versionStartIncluding": "3.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@salesforce.com"
}