Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-6612
HistoryDec 07, 2013 - 12:00 a.m.

CVE-2012-6612

2013-12-0700:00:00
ubuntu.com
ubuntu.com
15

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.002 Low

EPSS

Percentile

61.9%

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache
Solr before 4.1 allows remote attackers to have an unspecified impact via
XML data containing an external entity declaration in conjunction with an
entity reference, related to an XML External Entity (XXE) issue, different
vectors than CVE-2013-6407.

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.002 Low

EPSS

Percentile

61.9%