- CVE ID
- CVE-2019-14900
- CVE Description
- A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
- Published
- May 20, 2020
- CVSS Score & Severity
6.5Medium
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS Score
- 1.696%
- KEV Status
Not in KEV Catalog: No known exploits
- Source
- National Vulnerability Database