First published: Tue Jan 15 2019(Updated: )
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-dom4j | <0:2.1.3-1.redhat_00001.1.el6ea | 0:2.1.3-1.redhat_00001.1.el6ea |
redhat/eap7-elytron-web | <0:1.2.5-1.Final_redhat_00001.1.el6ea | 0:1.2.5-1.Final_redhat_00001.1.el6ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-13.SP3_redhat_00011.1.el6ea | 0:2.3.5-13.SP3_redhat_00011.1.el6ea |
redhat/eap7-hal-console | <0:3.0.23-1.Final_redhat_00001.1.el6ea | 0:3.0.23-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate | <0:5.3.17-1.Final_redhat_00001.1.el6ea | 0:5.3.17-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate-validator | <0:6.0.20-1.Final_redhat_00001.1.el6ea | 0:6.0.20-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar | <0:1.4.22-1.Final_redhat_00001.1.el6ea | 0:1.4.22-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-databind | <0:2.9.10.4-1.redhat_00001.1.el6ea | 0:2.9.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jboss-genericjms | <0:2.0.6-1.Final_redhat_00001.1.el6ea | 0:2.0.6-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-logmanager | <0:2.1.15-1.Final_redhat_00001.1.el6ea | 0:2.1.15-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-modules | <0:1.8.10-1.Final_redhat_00001.1.el6ea | 0:1.8.10-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.3.1-13.Final_redhat_00014.1.el6ea | 0:1.3.1-13.Final_redhat_00014.1.el6ea |
redhat/eap7-jboss-xnio-base | <0:3.7.6-4.SP3_redhat_00001.1.el6ea | 0:3.7.6-4.SP3_redhat_00001.1.el6ea |
redhat/eap7-resteasy | <0:3.6.1-10.SP9_redhat_00001.1.el6ea | 0:3.6.1-10.SP9_redhat_00001.1.el6ea |
redhat/eap7-undertow | <0:2.0.30-4.SP4_redhat_00001.1.el6ea | 0:2.0.30-4.SP4_redhat_00001.1.el6ea |
redhat/eap7-weld-core | <0:3.0.6-4.Final_redhat_00004.1.el6ea | 0:3.0.6-4.Final_redhat_00004.1.el6ea |
redhat/eap7-wildfly | <0:7.2.9-4.GA_redhat_00003.1.el6ea | 0:7.2.9-4.GA_redhat_00003.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.6.8-1.Final_redhat_00001.1.el6ea | 0:1.6.8-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-client | <0:1.0.22-1.Final_redhat_00001.1.el6ea | 0:1.0.22-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-transaction-client | <0:1.1.11-1.Final_redhat_00001.1.el6ea | 0:1.1.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-dom4j | <0:2.1.3-1.redhat_00001.1.el7ea | 0:2.1.3-1.redhat_00001.1.el7ea |
redhat/eap7-elytron-web | <0:1.2.5-1.Final_redhat_00001.1.el7ea | 0:1.2.5-1.Final_redhat_00001.1.el7ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-13.SP3_redhat_00011.1.el7ea | 0:2.3.5-13.SP3_redhat_00011.1.el7ea |
redhat/eap7-hal-console | <0:3.0.23-1.Final_redhat_00001.1.el7ea | 0:3.0.23-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate | <0:5.3.17-1.Final_redhat_00001.1.el7ea | 0:5.3.17-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate-validator | <0:6.0.20-1.Final_redhat_00001.1.el7ea | 0:6.0.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar | <0:1.4.22-1.Final_redhat_00001.1.el7ea | 0:1.4.22-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-databind | <0:2.9.10.4-1.redhat_00001.1.el7ea | 0:2.9.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jboss-genericjms | <0:2.0.6-1.Final_redhat_00001.1.el7ea | 0:2.0.6-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-logmanager | <0:2.1.15-1.Final_redhat_00001.1.el7ea | 0:2.1.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-modules | <0:1.8.10-1.Final_redhat_00001.1.el7ea | 0:1.8.10-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.3.1-13.Final_redhat_00014.1.el7ea | 0:1.3.1-13.Final_redhat_00014.1.el7ea |
redhat/eap7-jboss-xnio-base | <0:3.7.6-4.SP3_redhat_00001.1.el7ea | 0:3.7.6-4.SP3_redhat_00001.1.el7ea |
redhat/eap7-resteasy | <0:3.6.1-10.SP9_redhat_00001.1.el7ea | 0:3.6.1-10.SP9_redhat_00001.1.el7ea |
redhat/eap7-undertow | <0:2.0.30-4.SP4_redhat_00001.1.el7ea | 0:2.0.30-4.SP4_redhat_00001.1.el7ea |
redhat/eap7-weld-core | <0:3.0.6-4.Final_redhat_00004.1.el7ea | 0:3.0.6-4.Final_redhat_00004.1.el7ea |
redhat/eap7-wildfly | <0:7.2.9-4.GA_redhat_00003.1.el7ea | 0:7.2.9-4.GA_redhat_00003.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.6.8-1.Final_redhat_00001.1.el7ea | 0:1.6.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-client | <0:1.0.22-1.Final_redhat_00001.1.el7ea | 0:1.0.22-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-transaction-client | <0:1.1.11-1.Final_redhat_00001.1.el7ea | 0:1.1.11-1.Final_redhat_00001.1.el7ea |
redhat/eap7-dom4j | <0:2.1.3-1.redhat_00001.1.el8ea | 0:2.1.3-1.redhat_00001.1.el8ea |
redhat/eap7-elytron-web | <0:1.2.5-1.Final_redhat_00001.1.el8ea | 0:1.2.5-1.Final_redhat_00001.1.el8ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-13.SP3_redhat_00011.1.el8ea | 0:2.3.5-13.SP3_redhat_00011.1.el8ea |
redhat/eap7-hal-console | <0:3.0.23-1.Final_redhat_00001.1.el8ea | 0:3.0.23-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate | <0:5.3.17-1.Final_redhat_00001.1.el8ea | 0:5.3.17-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-validator | <0:6.0.20-1.Final_redhat_00001.1.el8ea | 0:6.0.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar | <0:1.4.22-1.Final_redhat_00001.1.el8ea | 0:1.4.22-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jackson-databind | <0:2.9.10.4-1.redhat_00001.1.el8ea | 0:2.9.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jboss-genericjms | <0:2.0.6-1.Final_redhat_00001.1.el8ea | 0:2.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-logmanager | <0:2.1.15-1.Final_redhat_00001.1.el8ea | 0:2.1.15-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-modules | <0:1.8.10-1.Final_redhat_00001.1.el8ea | 0:1.8.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.3.1-13.Final_redhat_00014.1.el8ea | 0:1.3.1-13.Final_redhat_00014.1.el8ea |
redhat/eap7-jboss-xnio-base | <0:3.7.6-4.SP3_redhat_00001.1.el8ea | 0:3.7.6-4.SP3_redhat_00001.1.el8ea |
redhat/eap7-resteasy | <0:3.6.1-10.SP9_redhat_00001.1.el8ea | 0:3.6.1-10.SP9_redhat_00001.1.el8ea |
redhat/eap7-undertow | <0:2.0.30-4.SP4_redhat_00001.1.el8ea | 0:2.0.30-4.SP4_redhat_00001.1.el8ea |
redhat/eap7-weld-core | <0:3.0.6-4.Final_redhat_00004.1.el8ea | 0:3.0.6-4.Final_redhat_00004.1.el8ea |
redhat/eap7-wildfly | <0:7.2.9-4.GA_redhat_00003.1.el8ea | 0:7.2.9-4.GA_redhat_00003.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.6.8-1.Final_redhat_00001.1.el8ea | 0:1.6.8-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client | <0:1.0.22-1.Final_redhat_00001.1.el8ea | 0:1.0.22-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-transaction-client | <0:1.1.11-1.Final_redhat_00001.1.el8ea | 0:1.1.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-elytron-web | <0:1.6.2-1.Final_redhat_00001.1.el6ea | 0:1.6.2-1.Final_redhat_00001.1.el6ea |
redhat/eap7-glassfish-jsf | <0:2.3.9-11.SP11_redhat_00001.1.el6ea | 0:2.3.9-11.SP11_redhat_00001.1.el6ea |
redhat/eap7-hal-console | <0:3.2.9-1.Final_redhat_00001.1.el6ea | 0:3.2.9-1.Final_redhat_00001.1.el6ea |
redhat/eap7-infinispan | <0:9.4.19-1.Final_redhat_00001.1.el6ea | 0:9.4.19-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.7.1-7.Final_redhat_00009.1.el6ea | 0:1.7.1-7.Final_redhat_00009.1.el6ea |
redhat/eap7-jboss-xnio-base | <0:3.7.8-1.SP1_redhat_00001.1.el6ea | 0:3.7.8-1.SP1_redhat_00001.1.el6ea |
redhat/eap7-netty | <0:4.1.48-1.Final_redhat_00001.1.el6ea | 0:4.1.48-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly | <0:7.3.2-4.GA_redhat_00002.1.el6ea | 0:7.3.2-4.GA_redhat_00002.1.el6ea |
redhat/eap7-wildfly-common | <0:1.5.2-1.Final_redhat_00002.1.el6ea | 0:1.5.2-1.Final_redhat_00002.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.10.7-1.Final_redhat_00001.1.el6ea | 0:1.10.7-1.Final_redhat_00001.1.el6ea |
redhat/eap7-elytron-web | <0:1.6.2-1.Final_redhat_00001.1.el7ea | 0:1.6.2-1.Final_redhat_00001.1.el7ea |
redhat/eap7-glassfish-jsf | <0:2.3.9-11.SP11_redhat_00001.1.el7ea | 0:2.3.9-11.SP11_redhat_00001.1.el7ea |
redhat/eap7-hal-console | <0:3.2.9-1.Final_redhat_00001.1.el7ea | 0:3.2.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan | <0:9.4.19-1.Final_redhat_00001.1.el7ea | 0:9.4.19-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.7.1-7.Final_redhat_00009.1.el7ea | 0:1.7.1-7.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-xnio-base | <0:3.7.8-1.SP1_redhat_00001.1.el7ea | 0:3.7.8-1.SP1_redhat_00001.1.el7ea |
redhat/eap7-netty | <0:4.1.48-1.Final_redhat_00001.1.el7ea | 0:4.1.48-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <0:7.3.2-4.GA_redhat_00002.1.el7ea | 0:7.3.2-4.GA_redhat_00002.1.el7ea |
redhat/eap7-wildfly-common | <0:1.5.2-1.Final_redhat_00002.1.el7ea | 0:1.5.2-1.Final_redhat_00002.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.10.7-1.Final_redhat_00001.1.el7ea | 0:1.10.7-1.Final_redhat_00001.1.el7ea |
redhat/eap7-elytron-web | <0:1.6.2-1.Final_redhat_00001.1.el8ea | 0:1.6.2-1.Final_redhat_00001.1.el8ea |
redhat/eap7-glassfish-jsf | <0:2.3.9-11.SP11_redhat_00001.1.el8ea | 0:2.3.9-11.SP11_redhat_00001.1.el8ea |
redhat/eap7-hal-console | <0:3.2.9-1.Final_redhat_00001.1.el8ea | 0:3.2.9-1.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan | <0:9.4.19-1.Final_redhat_00001.1.el8ea | 0:9.4.19-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.7.1-7.Final_redhat_00009.1.el8ea | 0:1.7.1-7.Final_redhat_00009.1.el8ea |
redhat/eap7-jboss-xnio-base | <0:3.7.8-1.SP1_redhat_00001.1.el8ea | 0:3.7.8-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-netty | <0:4.1.48-1.Final_redhat_00001.1.el8ea | 0:4.1.48-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <0:7.3.2-4.GA_redhat_00002.1.el8ea | 0:7.3.2-4.GA_redhat_00002.1.el8ea |
redhat/eap7-wildfly-common | <0:1.5.2-1.Final_redhat_00002.1.el8ea | 0:1.5.2-1.Final_redhat_00002.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.10.7-1.Final_redhat_00001.1.el8ea | 0:1.10.7-1.Final_redhat_00001.1.el8ea |
Hibernate Hibernate Orm | <5.3.18 | |
Hibernate Hibernate Orm | >=5.4.0<5.4.18 | |
Redhat Build Of Quarkus | ||
Redhat Decision Manager | =7.0 | |
Redhat Fuse | <7.8.0 | |
Redhat Jboss Data Grid | =7.0.0 | |
Redhat Jboss Enterprise Application Platform | ||
Redhat Jboss Middleware Text-only Advisories | ||
Redhat Openstack | =10 | |
Redhat Openstack | =13 | |
Redhat Openstack | =14 | |
Redhat Single Sign-on | ||
Quarkus Quarkus | <=1.5.2 | |
Redhat Jboss Enterprise Application Platform | =7.3 | |
Redhat Jboss Enterprise Application Platform | =7.4 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Jboss Enterprise Application Platform | =7.2 | |
redhat/Hibernate ORM | <5.3.18 | 5.3.18 |
redhat/Hibernate ORM | <5.4.18 | 5.4.18 |
redhat/Hibernate ORM | <5.5.0. | 5.5.0. |
redhat/Hibernate ORM 5.3.17.Final-redhat | <00001 | 00001 |
maven/org.hibernate:hibernate-core | >=5.5.0.Alpha1<5.5.0.Beta1 | 5.5.0.Beta1 |
maven/org.hibernate:hibernate-core | >=5.4.0<5.4.18 | 5.4.18 |
maven/org.hibernate:hibernate-core | <5.3.18 | 5.3.18 |
All of | ||
Any of | ||
Redhat Jboss Enterprise Application Platform | =7.3 | |
Redhat Jboss Enterprise Application Platform | =7.4 | |
Redhat Enterprise Linux | =8.0 | |
All of | ||
Any of | ||
Redhat Jboss Enterprise Application Platform | =7.3 | |
Redhat Jboss Enterprise Application Platform | =7.4 | |
Redhat Enterprise Linux | =7.0 | |
All of | ||
Redhat Jboss Enterprise Application Platform | =7.3 | |
Redhat Enterprise Linux | =6.0 | |
All of | ||
Redhat Jboss Enterprise Application Platform | =7.2 | |
Redhat Enterprise Linux | =8.0 | |
All of | ||
Redhat Jboss Enterprise Application Platform | =7.2 | |
Redhat Enterprise Linux | =7.0 | |
All of | ||
Redhat Jboss Enterprise Application Platform | =7.2 | |
Redhat Enterprise Linux | =6.0 |
There is no currently known mitigation for this flaw.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)