V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2017-12629
DEB
CriticalConfirmedExploit available

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config …

CVSS
9.8
Critical
EPSS
0.94
p99
Published
2017-01-01
Updated
2017-01-01
Description

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

Tags · CWE
Pre-auth
CWE-138
CWE-611
CAPEC-15
CAPEC-34
CAPEC-105
CAPEC-221
Affected products
Eap7-activemq-artemisEap7-activemq-artemisEap7-hibernateEap7-hibernateEap7-ironjacamarEap7-ironjacamarEap7-jboss-ec2-eapEap7-jboss-ec2-eapEap7-jboss-remotingEap7-jboss-remotingEap7-jboss-xnio-baseEap7-jboss-xnio-baseEap7-jgroupsEap7-jgroupsEap7-lucene-solrEap7-lucene-solrEap7-resteasyEap7-resteasyEap7-undertowEap7-undertow
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.939 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
43009
exploitdb · https://www.exploit-db.com/exploits/43009
Enterprise
CVE-2017-12629
github-poc · https://github.com/captain-woof/cve-2017-12629
Enterprise
Affected software
ProductVendorStatus
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-hibernateTracked
eap7-hibernateTracked
eap7-ironjacamarTracked
eap7-ironjacamarTracked
eap7-jboss-ec2-eapTracked
eap7-jboss-ec2-eapTracked
eap7-jboss-remotingTracked
eap7-jboss-remotingTracked
eap7-jboss-xnio-baseTracked
eap7-jboss-xnio-baseTracked
eap7-jgroupsTracked
eap7-jgroupsTracked
eap7-lucene-solrTracked
eap7-lucene-solrTracked
eap7-resteasyTracked
eap7-resteasyTracked
eap7-undertowTracked
eap7-undertowTracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities