Impact
An improper privilege management flaw exists in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server, allowing a user with a low‑privileged REST role to elevate their privileges to administrator. This gives the attacker the ability to perform privileged operations and access sensitive data that should otherwise be restricted. The weakness corresponds to CWE‑269, which describes inconsistencies in authentication and authorization controls.
Affected Systems
The vulnerability affects Progress Software Corporation’s MarkLogic Server, specifically versions earlier than 11.3.6 for the 11.x line and preceding 12.0.3 for the 12.x line. Users of these releases should verify their installed version against these thresholds.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity. No EPSS score is published, and the vulnerability is not currently listed in the CISA KEV catalog, which suggests it is not being actively exploited at large scale. The likely attack vector is through authenticated HTTP requests to the REST query endpoints; the description implies that an attacker must first compromise or create a user account with a low‑privileged REST role. Access to the interfaces over a trusted network or from a client with proper credentials would be sufficient to exploit the flaw, hence the CNA’s recommended workaround of restricting network access to the REST interfaces and minimizing REST role assignments.
OpenCVE Enrichment