Product
Apache Tika-server versions prior to 1.18 are susceptible to unauthenticated remote command injection via malicious HTTP headers in PUT requests, allowing arbitrary code execution.