SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-14900

A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query.

MEDIUM 6.5EPSS 2.13%

Does this matter?

Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
2.13% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
hibernate/hibernate orm · redhat/build of quarkus · redhat/decision manager · redhat/fuse · redhat/jboss data grid · redhat/jboss enterprise application platform · redhat/jboss middleware text-only advisories · redhat/openstack · redhat/single sign-on · quarkus/quarkus
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.