CVE-2019-14900
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.3.18 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 7.0 | |
| Before 7.8.0 | |
| Version 7.0.0 | |
| All versions | |
| All versions | |
| Version 10 | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.4 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.3 |
Configuration G
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 8.0 |
Configuration H
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 7.0 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.2 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 6.0 |
References (6)
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.