CVE-2016-6652
MEDIUMPivotal Spring Data JPA <1.9.6-1.10.4 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/93276
Mitigation, Vendor Advisory x_refsource_confirm
https://jira.spring.io/browse/DATAJPA-965
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2016-6652
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201701-01
Patch x_refsource_confirm
https://github.com/spring-projects/spring-data-jpa/commit/b8e7fe
Scores
CVSS v3
5.6
EPSS
0.0082
EPSS Percentile
53.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-89
Status
published
Products (3)
org.springframework.data/spring-data-jpa
0 - 1.9.6Maven
pivotal_software/spring_data_jpa
1.10.2
pivotal_software/spring_data_jpa
< 1.9.4
Published
Oct 05, 2016
Tracked Since
Feb 18, 2026