Описание
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
A flaw was found in Hibernate ORM. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
Отчет
OpenDaylight: In RHOSP10, RHOSP13 and RHOSP14 editions of Red Hat OpenStack platform, the hibernate-jfa library shipped with OpenDaylight is contains a flaw in the processing of SQL queries. The hibernate-jha implemenation is not used in a vulnerable way in OpenDaylight, preventing the potential for SQL injection. Red Hat Satellite 6.2, 6.3 and 6.4 contains affected versions of hibernate-core in its candlepin component. However, that component does not use hibernate-core in a vulnerable way.
Меры по смягчению последствий
There is no currently known mitigation for this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | hibernate-core | Out of support scope | ||
| Red Hat Decision Manager 7 | hibernate-core-kie-server-ee7 | Will not fix | ||
| Red Hat JBoss BRMS 5 | hibernate-core | Not affected | ||
| Red Hat JBoss Data Grid 7 | hibernate-core | Affected | ||
| Red Hat JBoss Data Virtualization 6 | hibernate-core | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 5 | hibernate-core | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | hibernate-core | Not affected | ||
| Red Hat JBoss Enterprise Web Server 2 | hibernate4 | Not affected | ||
| Red Hat JBoss Fuse 6 | hibernate-core | Not affected | ||
| Red Hat JBoss Fuse Service Works 6 | hibernate-core | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 an ...
EPSS
6.5 Medium
CVSS3