CVE-2017-17717: Sonatype Nexus Repository Manager

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.

Affected products

  • Sonatype Nexus Repository Manager: up to and including 2.14.5

Published 2017-12-17. Last modified 2026-06-17.