{"schema_version":"1.7.5","id":"CVE-2019-14900","published":"2020-07-06T19:15:12.230Z","modified":"2026-07-08T05:54:47.088231558Z","aliases":["GHSA-8grg-q944-cch5"],"related":["SUSE-SU-2020:2650-1","SUSE-SU-2020:2832-1"],"details":"A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hibernate/hibernate-orm","events":[{"introduced":"0"},{"fixed":"677568d2e62ef8614d192a3a81aed095bef38262"},{"introduced":"7759404259a8715927485fa1bc051da1f0dc9d9b"},{"fixed":"ab9de8e428df4202ae9ed22787a5d90f2e87203a"}],"database_specific":{"cpe":"cpe:2.3:a:hibernate:hibernate_orm:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.3.18"},{"introduced":"5.4.0"},{"fixed":"5.4.18"}],"source":"CPE_RANGE"}}],"versions":["5.4.17","5.4.16","5.4.15","5.3.17","5.4.14","5.3.16","5.4.13","5.4.12","5.4.11","5.3.15","5.4.10","5.4.9","5.3.14","5.4.8","5.4.7","5.3.13","5.4.6","5.4.5","5.3.12","5.3.11","5.4.4","5.4.3","5.3.10","5.4.2","5.3.9","5.3.8","5.4.1","5.4.0","5.3.7","5.3.6","5.3.5","5.3.4","5.3.3","5.3.2","5.3.1","5.3.0.Final","5.3.0.CR2","5.3.0.Beta2","5.3.0.Beta1","5.2.12","5.2.11","5.2.10","5.2.9","5.2.8","5.2.7","5.2.6","5.2.5","5.2.4","5.2.3","5.2.2","5.2.1","5.2.0","5.1.0","5.0.0.Final","5.0.0.CR4","5.0.0.CR3","5.0.0.CR2","5.0.0.CR1","5.0.0.Beta2","5.0.0.Beta1","4.3.6.Final","4.3.5.Final","4.3.4.Final","4.3.3.Final","4.3.2.Final","4.3.1.Final","4.3.0.CR2","4.3.0.CR1","4.3.0.Beta5","4.3.0.Beta4","4.3.0.Beta3","4.3.0.Beta2","4.3.0.Beta1","4.1.5.SP1","4.1.5.Final","4.1.4.Final","4.1.3.Final","4.1.2.Final","4.1.2","4.1.1","4.1.0.Final","4.0.1","4.0.0.Final","4.0.0.CR7","4.0.0.CR6","4.0.0.CR5","4.0.0.CR4","4.0.0.CR3","4.0.0.CR2","4.0.0.CR1","4.0.0.Beta5","4.0.0.Beta4","4.0.0.Beta3","4.0.0.Beta2","4.0.0.Beta1","4.0.0.Alpha2","4.0.0.Alpha1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14900.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/quarkusio/quarkus","events":[{"introduced":"0"},{"last_affected":"1a16fc7479f91522d1c7a0c29e24e2ac10465196"}],"database_specific":{"cpe":"cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.5.2"}],"source":"CPE_RANGE"}}],"versions":["1.5.2.Final"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14900.json"}}],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44%40%3Cdev.turbine.apache.org%3E"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220210-0020/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1666499"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:redhat:fuse:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"7.8.0"}],"source":"CPE_RANGE","vendor_product":"redhat:fuse"},{"cpes":["cpe:2.3:a:redhat:decision_manager:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"redhat:decision_manager"},{"cpes":["cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.0"}],"source":"CPE_STRING","vendor_product":"redhat:jboss_data_grid"},{"cpes":["cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.3"},{"last_affected":"7.3"},{"introduced":"7.4"},{"last_affected":"7.4"},{"introduced":"7.3"},{"last_affected":"7.3"},{"introduced":"7.4"},{"last_affected":"7.4"},{"introduced":"7.3"},{"last_affected":"7.3"},{"introduced":"7.2"},{"last_affected":"7.2"},{"introduced":"7.2"},{"last_affected":"7.2"},{"introduced":"7.2"},{"last_affected":"7.2"}],"source":"CPE_STRING","vendor_product":"redhat:jboss_enterprise_application_platform"},{"cpes":["cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:14:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"10"},{"last_affected":"10"},{"introduced":"13"},{"last_affected":"13"},{"introduced":"14"},{"last_affected":"14"}],"source":"CPE_STRING","vendor_product":"redhat:openstack"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}