Michael Stepankin and Olga Barinova discovered that Apache Solr was vulnerable to an XXE attack. An attacker could use this vulnerability to remotely execute code.
{ "binaries": [ { "binary_name": "liblucene3-contrib-java", "binary_version": "3.6.2+dfsg-8ubuntu0.1" }, { "binary_name": "liblucene3-java", "binary_version": "3.6.2+dfsg-8ubuntu0.1" }, { "binary_name": "liblucene3-java-doc", "binary_version": "3.6.2+dfsg-8ubuntu0.1" }, { "binary_name": "libsolr-java", "binary_version": "3.6.2+dfsg-8ubuntu0.1" }, { "binary_name": "solr-common", "binary_version": "3.6.2+dfsg-8ubuntu0.1" }, { "binary_name": "solr-jetty", "binary_version": "3.6.2+dfsg-8ubuntu0.1" }, { "binary_name": "solr-tomcat", "binary_version": "3.6.2+dfsg-8ubuntu0.1" } ], "availability": "No subscription required" }