Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache solr vulnerabilities and exploits
(subscribe to this query)
641
VMScore
CVE-2016-5662
Accellion Kiteworks appliances before kw2016.03.00 use setuid-root permissions for /opt/bin/cli, which allows local users to gain privileges via unspecified vectors.
Accellion Kiteworks Appliance
605
VMScore
CVE-2021-44548
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an malicious user to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network. If the attacker has wider access to the network, th...
Apache Solr
578
VMScore
CVE-2020-9492
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.
Apache Hadoop
Apache Solr 8.6.0
Apache Solr 8.6.2
Oracle Financial Services Crime And Compliance Management Studio 8.0.8.2.0
Oracle Financial Services Crime And Compliance Management Studio 8.0.8.3.0
578
VMScore
CVE-2020-13941
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBack...
Apache Solr
571
VMScore
CVE-2021-29943
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions before 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receivin...
Apache Solr
571
VMScore
CVE-2013-6407
The UpdateRequestHandler for XML in Apache Solr prior to 4.1 allows remote malicious users to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Apache Solr 3.6.1
Apache Solr 3.6.0
Apache Solr 4.0.0
Apache Solr 3.6.2
Apache Solr
571
VMScore
CVE-2013-6408
The DocumentAnalysisRequestHandler in Apache Solr prior to 4.3.1 does not properly use the EmptyEntityResolver, which allows remote malicious users to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, relate...
Apache Solr 4.0.0
Apache Solr 3.6.1
Apache Solr 4.2.1
Apache Solr 3.6.0
Apache Solr 4.2.0
Apache Solr 3.6.2
Apache Solr 4.1.0
Apache Solr
570
VMScore
CVE-2017-11693
MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient and ...
Medhost Medhost Document Management System -
570
VMScore
CVE-2017-11694
MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with Apache Solr may be able to obtain or modify sensitive patient and financi...
Medhost Medhost Document Management System -
534
VMScore
CVE-2017-9803
Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e...
Apache Solr 6.2.1
Apache Solr 6.4.0
Apache Solr 6.2.0
Apache Solr 6.4.1
Apache Solr 6.5.0
Apache Solr 6.4.2
Apache Solr 6.5.1
Apache Solr 6.3.0
Apache Solr 6.6.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »