Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2017-1000190

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF,…

Technology

Apache Solr

CVSS Score

9.1 / 10.0

Affected Versions

8.4.1

Upstream Fix

See upstream advisory

Published

November 17, 2017

OSSeva Coverage

Fixed upstream

Description

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

Is your Apache Solr deployment affected?

If you're running 8.4.1, you need this patch. Book a discovery call to get covered.