An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
{
"cpes": [
"cpe:2.3:a:apache:solr:8.8.1:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:solr:8.9:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*"
],
"severity": "High"
}