Michael Stepankin and Olga Barinova discovered that Apache Solr was vulnerable to an XXE attack. An attacker could use this vulnerability to remotely execute code.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "3.6.2+dfsg-8ubuntu0.1", "binary_name": "liblucene3-contrib-java" }, { "binary_version": "3.6.2+dfsg-8ubuntu0.1", "binary_name": "liblucene3-java" }, { "binary_version": "3.6.2+dfsg-8ubuntu0.1", "binary_name": "liblucene3-java-doc" }, { "binary_version": "3.6.2+dfsg-8ubuntu0.1", "binary_name": "libsolr-java" }, { "binary_version": "3.6.2+dfsg-8ubuntu0.1", "binary_name": "solr-common" }, { "binary_version": "3.6.2+dfsg-8ubuntu0.1", "binary_name": "solr-jetty" }, { "binary_version": "3.6.2+dfsg-8ubuntu0.1", "binary_name": "solr-tomcat" } ] }