CVE-2020-25638

Description

A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

Risk Information

Base Score
7.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.519

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle WebLogic Server 14.1.1.0.0Windows
Vulnerabilities CVE-2020-25638 are fixed in Hibernate-hibernate-core 5.4.24Windows
Vulnerabilities CVE-2020-25638 are fixed in Hibernate-hibernate-core 5.3.20Windows
libhibernate3-java security update(DSA-4908-1) libhibernate3-java_3.6.10.Final-9+deb10u1_all.debLinux
Relational Persistence for Idiomatic Java (USN-6845-1) libhibernate3-java_3.6.10.Final-9+deb10u1build0.20.04.1_all.debLinux
Vulnerabilities CVE-2020-25638 are fixed in Hibernate-hibernate-core for Linux 5.4.24Linux
Vulnerabilities CVE-2020-25638 are fixed in Hibernate-hibernate-core for Linux 5.3.20Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234