CVE-2020-25638
Last modified
CVE-2020-25638 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. EPSS estimates a 2.91% chance of exploitation in the next 30 days.
Description
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hibernate | Hibernate Orm | < 5.3.20 |
| Hibernate | Hibernate Orm | >= 5.4.0, < 5.4.24 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Quarkus | Quarkus | <= 1.9.2 |
| Oracle | Communications Cloud Native Core Console | 1.9.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 19.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1881353Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00000.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4908Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1881353Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00000.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4908Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25638?
How severe is CVE-2020-25638?
How do I fix CVE-2020-25638?
Are you affected by CVE-2020-25638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
