References https://www.cnblogs.com/null1433/p/12723729.html https://www.anquanke.com/post/id/193208 https://github.com/hktalent/MyDocs/blob/main/Apache%20Solr%20JMX%E6%9C%8D%E5%8A%A1%20RCE%20CVE-2019-12409.md https://blog.csdn.net/ll_515/article/details/128739785 https://cloud.tencent.com/developer/article/1541836 https://www.tenablecloud.cn/plugins/nessus/132315 https://blog.nsfocus.net/cve-2019-12409/ https://avd.aliyun.com/detail?id=AVD-2019-12409 https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/Apache%20Solr/%EF%BC%88CVE-2019-12409%EF%BC%89Apache%20Solr%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://www.cnblogs.com/Sylon/p/11927518.html https://nvd.nist.gov/vuln/detail/CVE-2019-12409 https://www.rapid7.com/db/vulnerabilities/apache-solr-cve-2019-12409/ https://github.com/jas502n/CVE-2019-12409 https://issues.apache.org/jira/browse/SOLR-13647 https://www.tenable.com/cve/CVE-2019-12409
Related Vulnerabilities泛微ecology8 getCptInfoMap 存在SQL注入漏洞PoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2025-51683: mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCEPoCCVE-2026-0561: Shield Security <= 21.0.8 - Unauthenticated Reflected XSSPoCCVE-2026-0650: OpenFlagr <= 1.1.18 - Authentication BypassPoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codePoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-21875: ClipBucket v5 <= 5.5.2 - Unauthenticated Blind SQL InjectionPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalPoCCVE-2026-48558: SimpleHelp <=5.5.15 - OIDC JWT Authentication Bypass