VDB
RHSA-2021%3A2562
RHSA-2021%3A2562
PUBLISHED
CVSS 7.400000095367432 HIGH
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 5 |
Timeline
- Jun 29, 2021 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2021:2562 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1881353 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1934032 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1934061 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2562.json advisory
- https://access.redhat.com/security/cve/CVE-2020-25638 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25638 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25638 advisory
- https://access.redhat.com/security/cve/CVE-2021-25122 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-25122 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-25122 advisory
- http://mail-archives.apache.org/mod_mbox/tomcat-announce/202103.mbox/%3Cb7626398-5e6d-1639-4e9e-e41b34af84de%40apache.org%3E advisory
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0.2 advisory
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.63 advisory
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.43 advisory
- https://access.redhat.com/security/cve/CVE-2021-25329 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-25329 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-25329 advisory
- http://mail-archives.apache.org/mod_mbox/tomcat-announce/202103.mbox/%3C811bba77-e74e-9f9b-62ca-5253a09ba84f%40apache.org%3E advisory
…and 1 more