CVE-2020-25638

EUVD-2022-1070
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA-ADPADP
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
hibernatehibernate_orm
𝑥
< 5.3.20
hibernatehibernate_orm
5.4.0 ≤
𝑥
< 5.4.24
debiandebian_linux
9.0
debiandebian_linux
10.0
quarkusquarkus
𝑥
≤ 1.9.2
oraclecommunications_cloud_native_core_console
1.9.0
oracleretail_customer_management_and_segmentation_foundation
19.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libhibernate3-java
bookworm
3.6.10.Final-12
fixed
bullseye
3.6.10.Final-11
fixed
sid
3.6.10.Final-12
fixed
trixie
3.6.10.Final-12
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libhibernate3-java
bionic
Fixed 3.6.10.Final-9ubuntu0.18.04.1~esm1
released
focal
Fixed 3.6.10.Final-9+deb10u1build0.20.04.1
released
groovy
ignored
hirsute
ignored
impish
ignored
jammy
not-affected
kinetic
ignored
lunar
ignored
mantic
not-affected
noble
not-affected
trusty
dne
xenial
Fixed 3.6.10.Final-4ubuntu0.1~esm1
released