An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
Restrict Hadoop integration privileges to users who require MLCP or Hadoop integration. Restrict network access to XDBC App Servers used for MLCP operations to trusted hosts. Disable XDBC App Servers used for MLCP if they are not required.