CVE Database
/

CVE-2020-25638

Back to search

CVE-2020-25638

Published: Dec 2, 2020

Modified: Apr 23, 2025

PUBLISHED

Description

A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

VendorProductVersions

n/a

hibernate-core

affected
Hibernate ORM versions before 5.4.24.Final

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now