Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-25638
Description:A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Test IDs: 1.3.6.1.4.1.25623.1.0.704908   1.3.6.1.4.1.25623.1.0.892512   1.3.6.1.4.1.25623.1.1.12.2024.6845.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-25638
Debian Security Information: DSA-4908 (Google Search)
https://www.debian.org/security/2021/dsa-4908
https://bugzilla.redhat.com/show_bug.cgi?id=1881353
https://bugzilla.redhat.com/show_bug.cgi?id=1881353
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://lists.debian.org/debian-lts-announce/2021/01/msg00000.html
https://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df@%3Ccommits.turbine.apache.org%3E
https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44@%3Cdev.turbine.apache.org%3E




© 1998-2025 E-Soft Inc. All rights reserved.