Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
Low
Attack Vector
Network
0

CVE-2019-14900

Disclosure Date: July 06, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.5 Medium
Impact Score:
3.6
Exploitability Score:
2.8
Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
None
Availability (A):
None

General Information

Vendors

  • hibernate,
  • quarkus,
  • redhat

Products

  • build of quarkus -,
  • decision manager 7.0,
  • fuse,
  • hibernate orm,
  • jboss data grid 7.0.0,
  • jboss enterprise application platform -,
  • jboss enterprise application platform 7.2,
  • jboss enterprise application platform 7.3,
  • jboss enterprise application platform 7.4,
  • jboss middleware text-only advisories -,
  • openstack 10,
  • openstack 13,
  • openstack 14,
  • quarkus,
  • single sign-on -

Additional Info

Technical Analysis