Hibernate Orm vulnerabilities
2 known vulnerabilities affecting hibernate/hibernate_orm.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-25638HIGHCVSS 7.4fixed in 5.3.20≥ 5.4.0, < 5.4.242020-12-02
CVE-2020-25638 [HIGH] CWE-89 CVE-2020-25638: A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest th
nvd
CVE-2019-14900MEDIUMCVSS 6.5fixed in 5.3.18≥ 5.4.0, < 5.4.18+3 more2020-07-06
CVE-2019-14900 [MEDIUM] CWE-89 CVE-2019-14900: A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks
cvelistv5nvd