CVE-2021-44548
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network. If the attacker has wider access to the network, this may lead to SMB attacks, which may result in: * The exfiltration of sensitive data such as OS user hashes (NTLM/LM hashes), * In case of misconfigured systems, SMB Relay Attacks which can lead to user impersonation on SMB Shares or, in a worse-case scenario, Remote Code Execution This issue affects all Apache Solr versions prior to 8.11.1. This issue only affects Windows.
Scoring
- CVSS base score
- 0.27
- EPSS probability
- 6.66%
- CWE
- CWE-40, CWE-20
- Published
- 2021-12-23
- Last modified
- 2026-03-13
Affected products
- Apache Software Foundation Apache Solr
Weakness type
Related vulnerabilities
- CVE-2026-25039 — The application evaluate UNC path in workspace name
- CVE-2026-27615 — ADB-Explorer: UNC Path Support in ManualAdbPath Leads to Remote Code Execution (RCE)
- CVE-2025-32103 — CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the...
- CVE-2023-29446 — Improper Input Validation in PTC's Kepware KEPServerEX