Описание
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
Уязвимые конфигурации
Конфигурация 1Версия до 11.3.6 (исключая)Версия от 12.0.0 (включая) до 12.0.3 (исключая)
Одно из
cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.00524
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.8
github
около 1 месяца назад
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
EPSS
Процентиль: 43%
0.00524
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-287