Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-25638


A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.


Published

2020-12-02T15:15:12.377

Last Modified

2025-04-23T20:15:19.037

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-89
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hibernate hibernate_orm < 5.3.20 Yes
Application hibernate hibernate_orm < 5.4.24 Yes
Operating System debian debian_linux 9.0 Yes
Operating System debian debian_linux 10.0 Yes
Application quarkus quarkus ≤ 1.9.2 Yes
Application oracle communications_cloud_native_core_console 1.9.0 Yes
Application oracle retail_customer_management_and_segmentation_foundation 19.0 Yes

References