CVE-2020-25638
Summary
| CVE | CVE-2020-25638 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-02 15:15:00 UTC |
| Updated | 2023-11-07 03:20:00 UTC |
| Description | A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [turbine-dev] 20211015 Fulcrum Security Hibernate Module |
|
lists.apache.org |
|
| Debian -- Security Information -- DSA-4908-1 libhibernate3-java |
DEBIAN |
www.debian.org |
|
| 1881353 – (CVE-2020-25638) CVE-2020-25638 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used |
MISC |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [SECURITY] [DLA 2512-1] libhibernate3-java security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [turbine-commits] 20211018 [turbine-fulcrum-security] 02/02: disable module hibernate (JIRA issue TRB-103), update docs, remove suppression |
|
lists.apache.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150676 Oracle WebLogic Server Multiple Vulnerabilities (APR-2023)
- 178572 Debian Security Update for libhibernate3-java (DSA 4908-1)
- 239760 Red Hat Update for red hat jboss web server 5.5.0 (RHSA-2021:2561)
- 87542 Oracle WebLogic Server Multiple Vulnerabilities (CPUAPR2023)