CVE-2020-25638

A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
redhatCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
hibernatehibernate_orm
𝑥
< 5.3.20
hibernatehibernate_orm
5.4.0 ≤
𝑥
< 5.4.24
debiandebian_linux
9.0
debiandebian_linux
10.0
quarkusquarkus
𝑥
≤ 1.9.2
oraclecommunications_cloud_native_core_console
1.9.0
oracleretail_customer_management_and_segmentation_foundation
19.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libhibernate3-java
bullseye
3.6.10.Final-11
fixed
sid
3.6.10.Final-12
fixed
trixie
3.6.10.Final-12
fixed
bookworm
3.6.10.Final-12
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libhibernate3-java
noble
not-affected
mantic
not-affected
lunar
ignored
kinetic
ignored
jammy
not-affected
impish
ignored
hirsute
ignored
groovy
ignored
focal
Fixed 3.6.10.Final-9+deb10u1build0.20.04.1
released
bionic
Fixed 3.6.10.Final-9ubuntu0.18.04.1~esm1
released
xenial
Fixed 3.6.10.Final-4ubuntu0.1~esm1
released
trusty
dne