Lucene search

K
cveRedhatCVE-2019-14900
HistoryJul 06, 2020 - 7:15 p.m.

CVE-2019-14900

2020-07-0619:15:12
CWE-89
redhat
web.nvd.nist.gov
168
sql injection
hibernate orm
cve-2019-14900
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

42.5%

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

Affected configurations

Nvd
Vulners
Node
hibernatehibernate_ormRange<5.3.18
OR
hibernatehibernate_ormRange5.4.05.4.18
Node
redhatbuild_of_quarkusMatch-text-only
OR
redhatdecision_managerMatch7.0
OR
redhatfuseRange<7.8.0
OR
redhatjboss_data_gridMatch7.0.0
OR
redhatjboss_enterprise_application_platformMatch-text-only
OR
redhatjboss_middleware_text-only_advisoriesMatch-
OR
redhatopenstackMatch10
OR
redhatopenstackMatch13
OR
redhatopenstackMatch14
OR
redhatsingle_sign-onMatch-text-only
Node
quarkusquarkusRange1.5.2
Node
redhatjboss_enterprise_application_platformMatch7.3
OR
redhatjboss_enterprise_application_platformMatch7.4
AND
redhatenterprise_linuxMatch8.0
Node
redhatjboss_enterprise_application_platformMatch7.3
OR
redhatjboss_enterprise_application_platformMatch7.4
AND
redhatenterprise_linuxMatch7.0
Node
redhatjboss_enterprise_application_platformMatch7.3
AND
redhatenterprise_linuxMatch6.0
Node
redhatjboss_enterprise_application_platformMatch7.2
AND
redhatenterprise_linuxMatch8.0
Node
redhatjboss_enterprise_application_platformMatch7.2
AND
redhatenterprise_linuxMatch7.0
Node
redhatjboss_enterprise_application_platformMatch7.2
AND
redhatenterprise_linuxMatch6.0
VendorProductVersionCPE
hibernatehibernate_orm*cpe:2.3:a:hibernate:hibernate_orm:*:*:*:*:*:*:*:*
redhatbuild_of_quarkus-cpe:2.3:a:redhat:build_of_quarkus:-:*:*:*:text-only:*:*:*
redhatdecision_manager7.0cpe:2.3:a:redhat:decision_manager:7.0:*:*:*:*:*:*:*
redhatfuse*cpe:2.3:a:redhat:fuse:*:*:*:*:*:*:*:*
redhatjboss_data_grid7.0.0cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*
redhatjboss_enterprise_application_platform-cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
redhatjboss_middleware_text-only_advisories-cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:-:*:*:*:*:*:*:*
redhatopenstack10cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*
redhatopenstack13cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
redhatopenstack14cpe:2.3:a:redhat:openstack:14:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

CNA Affected

[
  {
    "product": "Hibernate",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions before Hibernate ORM 5.3.18"
      },
      {
        "status": "affected",
        "version": "Versions before Hibernate ORM 5.4.18"
      },
      {
        "status": "affected",
        "version": "Versions before Hibernate ORM 5.5.0.Beta1"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

42.5%