CVE-2019-14900

Aliases:GHSA-8grg-q944-cch5
Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 06 Jul 2020, 18:35
Last modified:05 Aug 2024, 00:26

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
1.7% LOW
2% probability +0.29%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Jul 2020, 18:35
Published
Vulnerability first disclosed
05 Aug 2024, 00:26
Last Modified
Vulnerability information updated

Description

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 1.70% Percentile: 83%

Techniques & Countermeasures

  • CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Affected Systems

  • hibernatehibernate_orm

    < 5.3.18 | ≥ 5.4.0, < 5.4.18

  • org.hibernatehibernate-core

    < 5.3.18 | ≥ 5.4.0, < 5.4.18 | ≥ 5.5.0.Alpha1, < 5.5.0.Beta1

  • quarkusquarkus

    ≤ 1.5.2

  • redhatbuild_of_quarkus

    na

  • redhatdecision_manager

    7.0

  • redhatfuse

    < 7.8.0

  • redhatjboss_data_grid

    7.0.0

  • redhatjboss_enterprise_application_platform

    na | 7.3 | 7.4 | 7.2

  • redhatjboss_middleware_text-only_advisories

    na

  • redhatopenstack

    10 | 13 | 14

  • redhatsingle_sign-on

    na

References (11)