Vulnerability Description
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hibernate | Hibernate Orm | < 5.3.18 |
| Redhat | Build Of Quarkus | - |
| Redhat | Decision Manager | 7.0 |
| Redhat | Fuse | < 7.8.0 |
| Redhat | Jboss Data Grid | 7.0.0 |
| Redhat | Jboss Enterprise Application Platform | - |
| Redhat | Jboss Middleware Text-Only Advisories | - |
| Redhat | Openstack | 10 |
| Redhat | Single Sign-On | - |
| Quarkus | Quarkus | <= 1.5.2 |
| Redhat | Enterprise Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1666499Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9
- https://security.netapp.com/advisory/ntap-20220210-0020/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1666499Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9
- https://security.netapp.com/advisory/ntap-20220210-0020/Third Party Advisory
FAQ
What is CVE-2019-14900?
CVE-2019-14900 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is use...
How severe is CVE-2019-14900?
CVE-2019-14900 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14900?
Check the references section above for vendor advisories and patch information. Affected products include: Hibernate Hibernate Orm, Redhat Build Of Quarkus, Redhat Decision Manager, Redhat Fuse, Redhat Jboss Data Grid.