Description
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Published: 2020-12-02
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2512-1 libhibernate3-java security update
Debian DSA Debian DSA DSA-4908-1 libhibernate3-java security update
EUVD EUVD EUVD-2022-1070 A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Github GHSA Github GHSA GHSA-j8jw-g6fq-mp7h SQL injection in hibernate-core
History

Wed, 25 Jun 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Enterprise Application Platform Eus
CPEs cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Vendors & Products Redhat jboss Enterprise Application Platform Eus

Wed, 23 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Debian Debian Linux
Hibernate Hibernate Orm
Oracle Communications Cloud Native Core Console Retail Customer Management And Segmentation Foundation
Quarkus Quarkus
Redhat Integration Jboss Enterprise Application Platform Jboss Enterprise Application Platform Eus Jboss Enterprise Bpms Platform Jboss Enterprise Brms Platform Jboss Enterprise Web Server Jboss Fuse Jboss Single Sign On Openshift Application Runtimes Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-04-23T19:47:38.454Z

Reserved: 2020-09-16T00:00:00.000Z

Link: CVE-2020-25638

cve-icon Vulnrichment

Updated: 2024-08-04T15:40:35.438Z

cve-icon NVD

Status : Modified

Published: 2020-12-02T15:15:12.377

Modified: 2025-04-23T20:15:19.037

Link: CVE-2020-25638

cve-icon Redhat

Severity : Important

Publid Date: 2020-10-01T00:00:00Z

Links: CVE-2020-25638 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses