Impact
An improper privilege management issue in the Hadoop integration of Progress MarkLogic Server allows an authenticated user with a low-privileged Hadoop role to elevate privileges and perform privileged operations against the server’s Security database. Because the flaw lies in access control (CWE-269), the role boundary is not enforced correctly and a malicious actor can change security settings, potentially exposing, deleting, or corrupting sensitive data. The vulnerability is not a remote code execution flaw; it relies on the existence of valid credentials and Hadoop role assignments.
Affected Systems
The affected product is Progress Software Corporation’s MarkLogic Server. Versions before 11.3.6 and before 12.0.3 contain the vulnerable Hadoop integration module. The flaw exists in the MLCP component and the XDBC App Server used for Hadoop integration. Only nodes with Hadoop integration enabled are impacted; if a deployment does not use Hadoop integration, the software is not exposed to this issue.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.9, indicating a very high severity. No EPSS score is available, and it is not yet listed in the CISA KEV catalog. Attackers can exploit it by authenticating with a low-privileged Hadoop role, then using the Hadoop integration interface to gain higher privileges and execute privileged operations against the Security database. The attack requires no additional privileges beyond those granted by the low-privileged Hadoop role and no additional exploitation steps. Because the flaw directly impacts access control, the consequences include unauthorized data disclosure, modification, and potential compromise of system integrity.
OpenCVE Enrichment