Security Fix(es):
A flaw was found in Hibernate ORM. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.(CVE-2019-14900)
{ "severity": "Medium" }
{ "src": [ "hibernate3-3.6.10-25.oe1.src.rpm" ], "noarch": [ "hibernate3-3.6.10-25.oe1.noarch.rpm", "hibernate3-c3p0-3.6.10-25.oe1.noarch.rpm", "hibernate3-proxool-3.6.10-25.oe1.noarch.rpm", "hibernate3-testing-3.6.10-25.oe1.noarch.rpm", "hibernate3-help-3.6.10-25.oe1.noarch.rpm", "hibernate3-ehcache-3.6.10-25.oe1.noarch.rpm", "hibernate3-envers-3.6.10-25.oe1.noarch.rpm", "hibernate3-entitymanager-3.6.10-25.oe1.noarch.rpm" ] }