VDB
RHSA-2017%3A3124
RHSA-2017%3A3124
PUBLISHED
CVSS 9.800000190734863 CRITICAL
It was found that Apache Lucene would accept an object from an unauthenticated user that could be manipulated through subsequent post requests. An attacker could use this flaw to assemble an object that could permit execution of arbitrary code if the server enabled Apache Solr's Config API.
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.0 security update |
Timeline
- Nov 6, 2017 CVE Published
- Mar 5, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2017:3124 advisory
- https://access.redhat.com/security/vulnerabilities/CVE-2017-12629 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=7.0 advisory
- https://access.redhat.com/documentation/en/jboss-enterprise-application-platform/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1501529 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_3124.json advisory
- https://access.redhat.com/security/cve/CVE-2017-12629 advisory
- https://www.cve.org/CVERecord?id=CVE-2017-12629 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-12629 advisory