SQL Injection Vulnerability in Hibernate-core Affecting Oracle and Red Hat Products
CVE-2020-25638

7.4HIGH

Key Information:

Vendor

Hibernate

Vendor
CVE Published:
2 December 2020

What is CVE-2020-25638?

A vulnerability exists in the Hibernate-core library that allows SQL injection through the JPA Criteria API. This flaw emerges when unsanitized literals are utilized within SQL comments in queries, enabling attackers to potentially gain unauthorized access to sensitive information or carry out further malicious activities. The issue predominantly threatens the confidentiality and integrity of data processed by affected applications.

Affected Version(s)

hibernate-core Hibernate ORM versions before 5.4.24.Final

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.