Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20991
HistoryAug 05, 2019 - 9:09 a.m.

Remote Code Execution

2019-08-0509:09:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.935

Percentile

99.1%

Apach Solr DataImportHandler is vulnerable to remote code execution (RCE). The attack is possible because it allows an attacker to inject arbitrary code through request’s dataConfig parameter which is used for setting the whole DIH configuration when using debug mode of the DIH admin screen.

References