Lucene search

K
redhatcveRedhat.comRH:CVE-2019-14900
HistoryMay 12, 2020 - 3:40 p.m.

CVE-2019-14900

2020-05-1215:40:12
redhat.com
access.redhat.com
18

EPSS

0.001

Percentile

42.5%

A flaw was found in Hibernate ORM. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

Mitigation

There is no currently known mitigation for this flaw.