CVE-2016-6652

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
05/10/2016
Last modified:
12/04/2025

Description

SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal_software:spring_data_jpa:*:*:*:*:*:*:*:* 1.9.4 (including)
cpe:2.3:a:pivotal_software:spring_data_jpa:1.10.2:*:*:*:*:*:*:*