Greetings All,
A security scan flagged CVE-2025-24814 on one of our customer's ArcGIS Enterprise 11.3 environment.
Looking it up, this CVE is actually about Apache Solr, not Tomcat or Log4j (source: NVD). I can't find anything about it on the ArcGIS Trust Center, which makes me think ArcGIS Enterprise doesn't use Apache Solr at all.
Can anyone confirm:
- Does ArcGIS Enterprise (Server, Portal, GeoEvent, Data Store) use Apache Solr anywhere?
- If not, is it safe to say CVE-2025-24814 just doesn't apply to ArcGIS Enterprise?
Thanks!