CVE-2016-6652

MEDIUM

Pivotal Spring Data JPA <1.9.6-1.10.4 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93276
Mitigation, Vendor Advisory x_refsource_confirm
https://jira.spring.io/browse/DATAJPA-965
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2016-6652
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201701-01

Scores

CVSS v3 5.6
EPSS 0.0082
EPSS Percentile 53.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-89
Status published
Products (3)
org.springframework.data/spring-data-jpa 0 - 1.9.6Maven
pivotal_software/spring_data_jpa 1.10.2
pivotal_software/spring_data_jpa < 1.9.4
Published Oct 05, 2016
Tracked Since Feb 18, 2026