<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Hibernate ORM</title>
  <link>https://cvedaily.com/pages/tags/hibernate-orm.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/hibernate-orm.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Hibernate ORM</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-4594 – A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4594</guid>
    <pubDate>Mon, 23 Mar 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4594</strong></p>
  <p>A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy of the file erupt-data/erupt-jpa/src/main/java/xyz/erupt/jpa/dao/EruptJpaUtils.java. Such manipulation of the argument sort.field leads to sql injection hibernate. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The ven…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4593 – A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4593</guid>
    <pubDate>Mon, 23 Mar 2026 17:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4593</strong></p>
  <p>A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java of the component MCP Tool Interface. This manipulation causes sql injection hibernate. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted e…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23128 – In the Linux kernel, the following vulnerability has been resolved:

arm64: Set ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23128</guid>
    <pubDate>Sat, 14 Feb 2026 15:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23128</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  arm64: Set __nocfi on swsusp_arch_resume()  A DABT is reported[1] on an android based system when resume from hiberate. This happens because swsusp_arch_suspend_exit() is marked with SYM_CODE_*() and does not have a CFI hash, but swsusp_arch_resume() will attempt to verify the CFI hash when calling a copy of swsusp_arch_suspend_…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-23044 – In the Linux kernel, the following vulnerability has been resolved:

PM: hiberna...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23044</guid>
    <pubDate>Wed, 04 Feb 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-23044</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  PM: hibernate: Fix crash when freeing invalid crypto compressor  When crypto_alloc_acomp() fails, it returns an ERR_PTR value, not NULL.  The cleanup code in save_compressed_image() and load_compressed_image() unconditionally calls crypto_free_acomp() without checking for ERR_PTR, which causes crypto_acomp_tfm() to dereference a…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14969 – A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14969</guid>
    <pubDate>Mon, 26 Jan 2026 20:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14969</strong></p>
  <p>A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0603 – A flaw was found in Hibernate. A remote attacker with low privileges could explo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0603</guid>
    <pubDate>Fri, 23 Jan 2026 07:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0603</strong></p>
  <p>A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the app…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67280 – In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67280</guid>
    <pubDate>Fri, 09 Jan 2026 16:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67280</strong></p>
  <p>In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users and access sensitive data of another user.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-564</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-68230 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68230</guid>
    <pubDate>Tue, 16 Dec 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-68230</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: fix gpu page fault after hibernation on PF passthrough  On PF passthrough environment, after hibernate and then resume, coralgemm will cause gpu page fault.  Mode1 reset happens during hibernate, but partition mode is not restored on resume, register mmCP_HYP_XCP_CTL and mmCP_PSP_XCP_CTL is not right after resume. Wh…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10968 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10968</guid>
    <pubDate>Fri, 07 Nov 2025 13:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10968</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in GG Soft Software Services Inc. PaperWork allows Blind SQL Injection, SQL Injection.This issue affects PaperWork: from 6.1.0.9390 before 6.1.0.9398.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-39936 – In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-39936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-39936</guid>
    <pubDate>Sat, 04 Oct 2025 08:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-39936</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked()  When    9770b428b1a2 ("crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown")  moved the error messages dumping so that they don't need to be issued by the callers, it missed the case where __sev_firmware_shutdown() calls __sev_p…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-39865 – In the Linux kernel, the following vulnerability has been resolved:

tee: fix NU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-39865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-39865</guid>
    <pubDate>Fri, 19 Sep 2025 16:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-39865</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  tee: fix NULL pointer dereference in tee_shm_put  tee_shm_put have NULL pointer dereference:  __optee_disable_shm_cache --> 	shm = reg_pair_to_ptr(...);//shm maybe return NULL         tee_shm_free(shm); --> 		tee_shm_put(shm);//crash  Add check in tee_shm_put to fix it.  panic log: Unable to handle kernel paging request at virtu…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54385 – XWiki Platform is a generic wiki platform offering runtime services for applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54385</guid>
    <pubDate>Sat, 26 Jul 2025 04:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54385</strong></p>
  <p>XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions between 17.0.0-rc1 to 17.2.2 and versions 16.10.5 and below, it's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki#searchDocuments APIs pass queries directly to Hibernate without sanitization. Even when these APIs enforc…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-56158 – XWiki is a generic wiki platform. It's possible to execute any SQL query in Orac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56158</guid>
    <pubDate>Thu, 12 Jun 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-56158</strong></p>
  <p>XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki query validator does not sanitize functions that would be used in a simple select and Hibernate allows using any native function in an HQL query. This vulnerability is fixed in 16.10.2, 16.4.7, and 15.10.16.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-7071 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7071</guid>
    <pubDate>Tue, 27 Aug 2024 14:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-7071</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection.  This issue affects Brain Low-Code: before 2.1.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26093 – Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26093</guid>
    <pubDate>Mon, 20 Feb 2023 05:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26093</strong></p>
  <p>Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-1595 – LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1595</guid>
    <pubDate>Fri, 22 Apr 2016 10:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-1595</strong></p>
  <p>LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-3558 – ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Va...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3558</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-3558</strong></p>
  <p>ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4997 – gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4997</guid>
    <pubDate>Tue, 07 Sep 2010 18:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4997</strong></p>
  <p>gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532.  NOTE: this issue exists because of a regression that followed a gnome-p…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4996 – Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4996</guid>
    <pubDate>Tue, 07 Sep 2010 18:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4996</strong></p>
  <p>Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532.  NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, b…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-7240 – gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7240</guid>
    <pubDate>Tue, 07 Sep 2010 18:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-7240</strong></p>
  <p>gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-2532 – lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2532</guid>
    <pubDate>Fri, 03 Sep 2010 20:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-2532</strong></p>
  <p>lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2532">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
