An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:apache:solr:8.8.1:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:solr:8.9:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*"
]
}