All vulnerabilities
CVE-2016-6652
Improper Neutralization of Special Elements used in an SQL Command Pivotal Spring Data JPA
Description
SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.
Patch Available
Fix available through Seal Security. No upgrade required, protect your application instantly.
Fix without upgrading
Score
5.6
Severity
Medium
Ecosystem
Java
Publish Date
May 16, 2022
Modified Date
November 7, 2023
Score Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Versions

