CVE Vulnerabilities

CVE-2025-67280

SQL Injection: Hibernate

Published: Jan 09, 2026 | Modified: Jan 22, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users and access sensitive data of another user.

Weakness

Using Hibernate to execute a dynamic SQL statement built with user-controlled input can allow an attacker to modify the statement’s meaning or to execute arbitrary SQL commands.

Affected Software

NameVendorStart VersionEnd Version
Tim_flowTim-solutions*9.1.2 (excluding)

Potential Mitigations

References