VDB
RHSA-2020%3A5254
RHSA-2020%3A5254
PUBLISHED
CVSS 7.400000095367432 HIGH
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Single Sign-On 7.4.3 one-off |
Timeline
- Nov 30, 2020 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2020:5254 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1881353 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_5254.json advisory
- https://access.redhat.com/security/cve/CVE-2020-25638 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25638 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25638 advisory