Command injection in Apache Solr - CVE-2017-12629
Published: January 24, 2018 / Updated: August 15, 2025
Vulnerability identifier: #VU10219
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12629
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in the RunExecutableListener function due to insufficient security restrictions. A remote attacker can submit a specially crafted query to the affected system, inject arbitrary command and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the RunExecutableListener function due to insufficient security restrictions. A remote attacker can submit a specially crafted query to the affected system, inject arbitrary command and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Apache Solr
JBoss Data Grid
Debian Linux
Fedora
JBoss Enterprise Application Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Manager Open Editions
rh-java-common-lucene (Red Hat package)
lucene4
rh-java-common-lucene5 (Red Hat package)
lucene
JBoss Data Grid
Debian Linux
Fedora
JBoss Enterprise Application Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Manager Open Editions
rh-java-common-lucene (Red Hat package)
lucene4
rh-java-common-lucene5 (Red Hat package)
lucene
How to mitigate CVE-2017-12629
Install update from vendor's website.
Apache Solr - addressed in versions 5.5.5, 6.6.2, 7.1.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
rh-java-common-lucene (Red Hat package) - addressed in versions 4.8.0-6.9.el6, 4.8.0-6.9.el7
lucene4 - addressed in versions 4.10.4-11.fc25, 4.10.4-11.fc26, 4.10.4-11.fc27
rh-java-common-lucene5 (Red Hat package) - addressed in versions 5.4.1-2.4.el6, 5.4.1-2.4.el7
lucene - addressed in versions 5.5.0-5.fc25, 6.1.0-6.fc26, 6.1.0-6.fc27
JBoss Data Grid - update to 7.1.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
rh-java-common-lucene (Red Hat package) - addressed in versions 4.8.0-6.9.el6, 4.8.0-6.9.el7
lucene4 - addressed in versions 4.10.4-11.fc25, 4.10.4-11.fc26, 4.10.4-11.fc27
rh-java-common-lucene5 (Red Hat package) - addressed in versions 5.4.1-2.4.el6, 5.4.1-2.4.el7
lucene - addressed in versions 5.5.0-5.fc25, 6.1.0-6.fc26, 6.1.0-6.fc27
JBoss Data Grid - update to 7.1.1
Links to Public Exploits and PoC-codes
- Exploit #11853 - cve-2017-12629 (Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class.) (August 15, 2025)
- Exploit #1384 - Apache Solr 7.0.1 - XML External Entity Expansion / Remote Code Execution (March 18, 2020)
External References
Related Security Bulletins
- Remote code execution in Apache Solr
- Debian update for lucene-solr
- Red Hat update for Red Hat JBoss Enterprise Application Platform
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Red Hat Process Automation Manager 7.13
- Fedora 27 update for lucene
- Fedora 26 update for lucene
- Fedora 25 update for lucene
- Fedora 27 update for lucene4
- Fedora 26 update for lucene4
- Fedora 25 update for lucene4
- Multiple vulnerabilities in JBoss Data Grid 7.1
- Red Hat Software Collections update for rh-java-common-lucene5
- Red Hat Software Collections update for rh-java-common-lucene