Impact
This vulnerability allows an unauthenticated remote attacker to bypass password verification in the ODBC App Server of Progress MarkLogic Server before version 11.3.6 and 12.0.3, enabling the attacker to execute queries with the credentials of any named user known to the server, including administrators. The flaw represents an authentication bypass (CWE‑287) that could lead to unauthorized data access, modification, and administrative control.
Affected Systems
Progress Software Corporation MarkLogic Server versions earlier than 11.3.6 and 12.0.3 are impacted, particularly wherever the ODBC App Server component is enabled. Any deployment using these versions should assess whether the ODBC interface is in use.
Risk and Exploitability
The CVSS score of 9.8 classifies this issue as critical. Although EPSS data is not available and the vulnerability is not listed in CISA KEV, the risk remains high because the flaw allows remote exploitation without authentication. An attacker can reach the vulnerable ODBC port from any network that has connectivity, making exploitation possible when the port is exposed to untrusted or internet‑facing networks.
OpenCVE Enrichment