CVE Vulnerabilities

CVE-2025-8052

SQL Injection: Hibernate

Published: Oct 20, 2025 | Modified: Oct 28, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SQL Injection vulnerability in opentext Flipper allows SQL Injection. 

The vulnerability could allow a low privilege user to interact with the database in unintended ways and extract data by interacting with the HQL processor.

This issue affects Flipper: 3.1.2.

Weakness

Using Hibernate to execute a dynamic SQL statement built with user-controlled input can allow an attacker to modify the statement’s meaning or to execute arbitrary SQL commands.

Affected Software

Name Vendor Start Version End Version
Flipper Opentext 3.1.2 (including) 3.1.2 (including)

Potential Mitigations

References