Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring. This allows remote attackers to execute arbitrary code.
https://github.com/vasilerevnic/CVE-2017-15220-vxsearch-rce