CVE-2019-14900: Hibernate Orm

Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

Affected products

  • Hibernate Hibernate Orm: before 5.3.18 (fixed in 5.3.18); from 5.4.0, before 5.4.18 (fixed in 5.4.18)
  • Quarkus Quarkus: up to and including 1.5.2
  • Red Hat Build Of Quarkus: affected versions not specified
  • Red Hat Decision Manager: version 7.0 only
  • Red Hat Fuse: before 7.8.0 (fixed in 7.8.0)
  • Red Hat JBoss Data Grid: version 7.0.0 only
  • Red Hat JBoss Enterprise Application Platform: affected versions not specified; version 7.3 only; version 7.4 only; version 7.2 only
  • Red Hat JBoss Middleware Text-Only Advisories: affected versions not specified
  • Red Hat Openstack: version 10 only; version 13 only; version 14 only
  • Red Hat Single Sign-On: affected versions not specified

Published 2020-07-06. Last modified 2026-06-17.