CVE-2017-17717

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
17/12/2017
Last modified:
20/04/2025

Description

Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*:* 2.14.5 (including)