{"api_version":"1","generated_at":"2026-07-23T08:08:50+00:00","cve":"CVE-2012-6612","urls":{"html":"https://cve.report/CVE-2012-6612","api":"https://cve.report/api/cve/CVE-2012-6612.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-6612","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-6612"},"summary":{"title":"CVE-2012-6612","description":"The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.","state":"PUBLISHED","assigner":"mitre","published_at":"2013-12-07 21:55:09","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup","name":"http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ViewVC Exception","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-0029.html","name":"http://rhn.redhat.com/errata/RHSA-2014-0029.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://issues.apache.org/jira/browse/SOLR-3895","name":"https://issues.apache.org/jira/browse/SOLR-3895","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"[#SOLR-3895] For several reasons, disabling the resolving of external entities within the Solr UpdateRequestHandler for XML would be good. - ASF JIRA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-1844.html","name":"http://rhn.redhat.com/errata/RHSA-2013-1844.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-6612","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-6612","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"6612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"solr","cpe6":"4.0.0","cpe7":"alpha","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"6612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"solr","cpe6":"4.0.0","cpe7":"beta","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"6612","vulnerable":"1","versionEndIncluding":"4.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"solr","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2012","cve_id":"6612","cve":"CVE-2012-6612","epss":"0.013570000","percentile":"0.802110000","score_date":"2026-04-29","updated_at":"2026-04-30 00:13:22"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:36:02.073Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2014:0029","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0029.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://issues.apache.org/jira/browse/SOLR-3895"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup"},{"name":"RHSA-2013:1844","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-1844.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-09-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-03-05T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"RHSA-2014:0029","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0029.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://issues.apache.org/jira/browse/SOLR-3895"},{"tags":["x_refsource_CONFIRM"],"url":"http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup"},{"name":"RHSA-2013:1844","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-1844.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-6612","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"RHSA-2014:0029","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2014-0029.html"},{"name":"https://issues.apache.org/jira/browse/SOLR-3895","refsource":"CONFIRM","url":"https://issues.apache.org/jira/browse/SOLR-3895"},{"name":"http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup","refsource":"CONFIRM","url":"http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup"},{"name":"RHSA-2013:1844","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2013-1844.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-6612","datePublished":"2013-12-07T21:00:00.000Z","dateReserved":"2013-12-07T00:00:00.000Z","dateUpdated":"2024-08-06T21:36:02.073Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-12-07 21:55:09","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*","versionEndIncluding":"4.0.0","matchCriteriaId":"1887ADD7-5B71-4CC4-B003-1F50DAC3DFA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:solr:4.0.0:alpha:*:*:*:*:*:*","matchCriteriaId":"49D9F075-B18A-4634-8AA1-DE1399548838"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:solr:4.0.0:beta:*:*:*:*:*:*","matchCriteriaId":"0CFB9E78-22B2-4683-BD17-1600A3057FF3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"6612","Ordinal":"1","Title":"CVE-2012-6612","CVE":"CVE-2012-6612","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"6612","Ordinal":"1","NoteData":"The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.","Type":"Description","Title":"CVE-2012-6612"},{"CveYear":"2012","CveId":"6612","Ordinal":"2","NoteData":"2013-12-07","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"6612","Ordinal":"3","NoteData":"2014-03-05","Type":"Other","Title":"Modified"}]}}}