A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service.
Metrics
Affected Vendors & Products
References
History
Fri, 23 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 Jan 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service. |
| Title | org.hibernate/hibernate-core: Hibernate: Information disclosure and data deletion via second-order SQL injection | Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection |
| First Time appeared |
Redhat
Redhat amq Broker Redhat jboss Data Grid Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat openshift Ai Redhat openshift Devspaces Redhat optaplanner Redhat red Hat Single Sign On Redhat satellite |
|
| CPEs | cpe:/a:redhat:amq_broker:7 cpe:/a:redhat:jboss_data_grid:8 cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_enterprise_bpms_platform:7 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:openshift_ai cpe:/a:redhat:openshift_devspaces:3 cpe:/a:redhat:optaplanner:::el6 cpe:/a:redhat:red_hat_single_sign_on:7 cpe:/a:redhat:satellite:6 |
|
| Vendors & Products |
Redhat
Redhat amq Broker Redhat jboss Data Grid Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat openshift Ai Redhat openshift Devspaces Redhat optaplanner Redhat red Hat Single Sign On Redhat satellite |
|
| References |
|
Tue, 20 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | org.hibernate/hibernate-core: Hibernate: Information disclosure and data deletion via second-order SQL injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-01-23T06:31:38.975Z
Updated: 2026-01-23T15:33:36.471Z
Reserved: 2026-01-05T13:18:55.616Z
Link: CVE-2026-0603
Updated: 2026-01-23T15:33:32.484Z
Status : Received
Published: 2026-01-23T07:15:53.660
Modified: 2026-01-23T07:15:53.660
Link: CVE-2026-0603