Vulnerability Description
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mulesoft | Api Gateway | >= 2.0.0, <= 2.2.12 |
| Mulesoft | Mule Runtime | >= 3.0.0, <= 3.9.3 |
References
- https://help.salesforce.com/articleView?id=000351827&language=en_US&type=1&mode=Third Party Advisory
- https://help.salesforce.com/articleView?id=000351827&language=en_US&type=1&mode=Third Party Advisory
FAQ
What is CVE-2019-15631?
CVE-2019-15631 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
How severe is CVE-2019-15631?
CVE-2019-15631 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-15631?
Check the references section above for vendor advisories and patch information. Affected products include: Mulesoft Api Gateway, Mulesoft Mule Runtime.