Security Fix(es):
A flaw was found in Hibernate ORM. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.(CVE-2019-14900)
{
"severity": "Medium"
}{
"src": [
"hibernate3-3.6.10-25.oe1.src.rpm"
],
"noarch": [
"hibernate3-3.6.10-25.oe1.noarch.rpm",
"hibernate3-c3p0-3.6.10-25.oe1.noarch.rpm",
"hibernate3-proxool-3.6.10-25.oe1.noarch.rpm",
"hibernate3-testing-3.6.10-25.oe1.noarch.rpm",
"hibernate3-help-3.6.10-25.oe1.noarch.rpm",
"hibernate3-ehcache-3.6.10-25.oe1.noarch.rpm",
"hibernate3-envers-3.6.10-25.oe1.noarch.rpm",
"hibernate3-entitymanager-3.6.10-25.oe1.noarch.rpm"
]
}