November 26, 2019 By Shane Schick 2 min read

New exploit code has led researchers to reclassify a security threat aimed at the Linux enterprise search tool Apache Solr to “high severity status.”

Affected hardware could be hit with remote code execution (RCE) attacks that take advantage of a default configuration vulnerability, according to a blog post from Tenable.

Solr — which was originally designed to help those visiting the popular tech news site CNET look up information — has been run for the past 13 years by open-source organization Apache Software Foundation, which has continued to enhance its capabilities for other organizations. The exploit code discovery follows initial reports of a bug this past July, which were not considered as serious.

How the Solr Vulnerability Became a Critical Risk

Researchers originally believed the security issue with Solr would only allow cybercriminals and other third parties to access monitoring data. Further investigation showed, however, that using proof-of-concept code could allow malware to be uploaded and run on a Solr server, based on a hole in the 8983 port.

Although Windows users are reportedly not affected, the bug could be a powerful tool for misuse by anyone with network access to a Solr server and Java Management Extensions.

The Solr team issued a warning late last week, following the publication of revised proof-of-concept exploit code on the popular repository GitHub. Part of the concern stems from the fact that Apache Solr uses large volumes of compute power, which may be of interest to cryptocurrency miners and other cybercriminals.

Reducing the Risk of RCE Attacks

The Solr advisory suggested that anyone worried about being hit by an attack based on the exploit code could avoid the risk by using the “False” parameter for ENABLE_REMOTE_JMX_OPTS in their solr.in.sh file settings. The Solr team also suggested users ensure they are updated to version 8.3, though the Tenable post suggested many versions, including that one, were vulnerable to the bug.

Another way to stay safe from this and other RCE attacks is to invest in vulnerability management solutions or services that can identify, prioritize and remediate exploit code and other flaws in commonly used software applications.

More from

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

New proposed federal data privacy law suggests big changes

3 min read - After years of work and unsuccessful attempts at legislation, a draft of a federal data privacy law was recently released. The United States House Committee on Energy and Commerce released the American Privacy Rights Act on April 7, 2024. Several issues stood in the way of passing legislation in the past, such as whether states could issue tougher rules and if individuals could sue companies for privacy violations. With the American Privacy Rights Act of 2024, the U.S. government established…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today