Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-6408
Description:The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407.
Test IDs: 1.3.6.1.4.1.25623.1.0.903507   1.3.6.1.4.1.25623.1.0.108882  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-6408
55542
http://secunia.com/advisories/55542
59372
http://secunia.com/advisories/59372
RHSA-2013:1844
http://rhn.redhat.com/errata/RHSA-2013-1844.html
RHSA-2014:0029
http://rhn.redhat.com/errata/RHSA-2014-0029.html
[oss-security] 20131128 Re: CVE Request: Apache Solr XXE
http://www.openwall.com/lists/oss-security/2013/11/29/2
http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup
http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup
https://issues.apache.org/jira/browse/SOLR-4881
https://issues.apache.org/jira/browse/SOLR-4881




© 1998-2025 E-Soft Inc. All rights reserved.