VDB

CVE-2026-0603

CVE-2026-0603 PUBLISHED CVSS 8.300000190734863 HIGH

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service.

EPSS 0.07% · 22.5th percentile

Risk Scores

CVSS v3.1
8.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
EPSS Score
0.07%
22.5th percentile

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 70:7.4.24-4.GA_redhat_00002.1.el7eap, 0:7.4.24-4.GA_redhat_00002.1.el7eap
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7*, 0:5.3.38-1.Final_redhat_00001.1.el7eap
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 70:7.3.17-5.GA_redhat_00006.1.el7eap
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9*, 0:7.4.24-4.GA_redhat_00002.1.el9eap
Red HatRed Hat JBoss Enterprise Application Platform 7.4
Red HatRed Hat Data Grid 8
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 70:7.1.14-4.GA_redhat_00003.1.ep7.el7
Red HatRed Hat JBoss Enterprise Application Platform 8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 80:5.3.38-1.Final_redhat_00001.1.el8eap, 0:5.3.38-1.Final_redhat_00001.1.el8eap
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9*, 0:5.3.38-1.Final_redhat_00001.1.el9eap
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat Satellite 6
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7*
Red HatRed Hat Process Automation 7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 70:5.3.38-1.Final_redhat_00001.1.el7eap
Red HatRed Hat build of OptaPlanner 8
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 80:7.4.24-4.GA_redhat_00002.1.el8eap, *
Red HatRed Hat OpenShift Dev Spaces

…and 6 more

Timeline

  • Jan 23, 2026 CVE Published
  • Jan 23, 2026 EPSS Score
  • Jan 23, 2026 PoC Published
  • Jan 23, 2026 PoC Published
  • Jan 26, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 31, 2026 EPSS Score
  • Feb 2, 2026 EPSS Score
  • Feb 5, 2026 EPSS Score
  • Feb 8, 2026 EPSS Score
  • Feb 10, 2026 EPSS Score
  • Feb 13, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›