CVE-2020-25638
published 2020-12-02CVE-2020-25638: A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit…
PriorityP349high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
2.91%
85.4th percentile
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libhibernate3-java | < libhibernate3-java 3.6.10.Final-11 (bookworm) | libhibernate3-java 3.6.10.Final-11 (bookworm) |
| hibernate | hibernate_orm | < 5.3.20 | 5.3.20 |
| hibernate | hibernate_orm | >= 5.4.0 < 5.4.24 | 5.4.24 |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | retail_customer_management_and_segmentation_foundation | — | — |
| quarkus | quarkus | <= 1.9.2 | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_oracle7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Utilities Applications Risk Matrix: General (hibernate-core) — CVE-2020-25638
vendor_oracle·2024-04-15·CVSS 7.4
CVE-2020-25638 [HIGH] Oracle Oracle Utilities Applications Risk Matrix: General (hibernate-core) — CVE-2020-25638
Oracle Oracle Utilities Applications Risk Matrix: General (hibernate-core) vulnerability
CVE: CVE-2020-25638
CVSS: 7.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core (JBoss Enterprise Application Platform) — CVE-2020-25638
vendor_oracle·2023-04-15·CVSS 7.4
CVE-2020-25638 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Core (JBoss Enterprise Application Platform) — CVE-2020-25638
Oracle Oracle Fusion Middleware Risk Matrix: Core (JBoss Enterprise Application Platform) vulnerability
CVE: CVE-2020-25638
CVSS: 7.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Risk Matrix: CNC Console (hibernate-core) — CVE-2020-25638
vendor_oracle·2022-04-15·CVSS 7.4
CVE-2020-25638 [HIGH] Oracle Oracle Communications Risk Matrix: CNC Console (hibernate-core) — CVE-2020-25638
Oracle Oracle Communications Risk Matrix: CNC Console (hibernate-core) vulnerability
CVE: CVE-2020-25638
CVSS: 7.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Segment (Hibernate) — CVE-2020-25638
vendor_oracle·2021-07-15·CVSS 7.4
CVE-2020-25638 [HIGH] Oracle Oracle Retail Applications Risk Matrix: Segment (Hibernate) — CVE-2020-25638
Oracle Oracle Retail Applications Risk Matrix: Segment (Hibernate) vulnerability
CVE: CVE-2020-25638
CVSS: 7.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used
vendor_redhat·2020-10-01·CVSS 7.4
CVE-2020-25638 [HIGH] CWE-89 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used
hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow
Debian
CVE-2020-25638: libhibernate3-java - A flaw was found in hibernate-core in versions prior to and including 5.4.23.Fin...
vendor_debian·2020·CVSS 7.4
CVE-2020-25638 [HIGH] CVE-2020-25638: libhibernate3-java - A flaw was found in hibernate-core in versions prior to and including 5.4.23.Fin...
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Scope: local
bookworm: resolved (fixed in 3.6.10.Final-11)
bullseye: resolved (fixed in 3.6.10.Final-11)
forky: resolved (fixed in 3.6.10.Final-11)
sid: resolved (fixed in 3.6.10.Final-11)
trixie: resolved (fixed in 3.6.10.Final-11)
OSV
SQL injection in hibernate-core
osv·2022-02-09
CVE-2020-25638 [HIGH] SQL injection in hibernate-core
SQL injection in hibernate-core
A flaw was found in hibernate-core in versions prior to 5.3.20.Final and in 5.4.0.Final up to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
GHSA
SQL injection in hibernate-core
ghsa·2022-02-09
CVE-2020-25638 [HIGH] CWE-89 SQL injection in hibernate-core
SQL injection in hibernate-core
A flaw was found in hibernate-core in versions prior to 5.3.20.Final and in 5.4.0.Final up to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
OSV
CVE-2020-25638: A flaw was found in hibernate-core in versions prior to and including 5
osv·2020-12-02·CVSS 7.4
CVE-2020-25638 [HIGH] CVE-2020-25638: A flaw was found in hibernate-core in versions prior to and including 5
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1881353https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44%40%3Cdev.turbine.apache.org%3Ehttps://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df%40%3Ccommits.turbine.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/01/msg00000.htmlhttps://www.debian.org/security/2021/dsa-4908https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1881353https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44%40%3Cdev.turbine.apache.org%3Ehttps://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df%40%3Ccommits.turbine.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/01/msg00000.htmlhttps://www.debian.org/security/2021/dsa-4908https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2020-12-02
Published