Search
Search Results (12 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-7326 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 7.5 High |
| A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration. | ||||
| CVE-2026-7327 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 8.1 High |
| An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user. | ||||
| CVE-2026-7329 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 9.9 Critical |
| An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access. | ||||
| CVE-2026-7557 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 9.1 Critical |
| An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. | ||||
| CVE-2026-8709 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 9.9 Critical |
| An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database. | ||||
| CVE-2026-9190 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 9.1 Critical |
| An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently. | ||||
| CVE-2026-9192 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 9.8 Critical |
| An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators. | ||||
| CVE-2026-9193 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 9.9 Critical |
| An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database. | ||||
| CVE-2026-9195 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 9.3 Critical |
| A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf. | ||||
| CVE-2026-9203 | 1 Progress Software Corporation | 1 Marklogic Server | 2026-08-07 | 8.5 High |
| A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance. | ||||
| CVE-2025-7389 | 1 Progress Software Corporation | 1 Openedge | 2026-04-17 | N/A |
| A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself. The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile() methods exposed through the RMI interface. Misuse was limited only by OS-level authority of the AdminServer's elevated privileges granted and the user's access to these methods enabled through RMI. The exploitable methods have been removed thus eliminating their access through RMI or downstream of the RMI registry. | ||||
| CVE-2025-8095 | 1 Progress Software Corporation | 1 Openedge | 2026-04-17 | N/A |
| The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption. | ||||
Page 1 of 1.