« Volver al listado

Progress

Progress Marklogic Server: vulnerabilidades y CVE

Progress Marklogic Server tiene 10 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses10
Críticas7
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-9203Alta (8.5)0.34%—5 ago 2026
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints.…
CVE-2026-9195Crítica (9.3)0.65%—5 ago 2026
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary…
CVE-2026-9193Crítica (9.9)0.46%—5 ago 2026
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and…
CVE-2026-9192Crítica (9.8)0.83%—5 ago 2026
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the…
CVE-2026-9190Crítica (9.1)0.74%—5 ago 2026
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's…
CVE-2026-8709Crítica (9.9)0.46%—5 ago 2026
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate…
CVE-2026-7557Crítica (9.1)0.46%—5 ago 2026
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass…
CVE-2026-7329Crítica (9.9)0.57%—5 ago 2026
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to…
CVE-2026-7327Alta (8.1)0.39%—5 ago 2026
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate…
CVE-2026-7326Alta (8.8)0.21%—5 ago 2026
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation4
  2. T1210 Exploitation of Remote Services4
  3. T1190 Exploit Public-Facing Application3
  4. T1078 Valid Accounts2
  5. T1203 Exploitation for Client Execution2
  6. T1059.007 JavaScript1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Progress