CVE Vulnerabilities

CVE-2025-8052

SQL Injection: Hibernate

Published: Oct 20, 2025 | Modified: Oct 28, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL Injection vulnerability in opentext Flipper allows SQL Injection. 

The vulnerability could allow a low privilege user to interact with the database in unintended ways and extract data by interacting with the HQL processor.

This issue affects Flipper: 3.1.2.

Weakness

Using Hibernate to execute a dynamic SQL statement built with user-controlled input can allow an attacker to modify the statement’s meaning or to execute arbitrary SQL commands.

Affected Software

NameVendorStart VersionEnd Version
FlipperOpentext3.1.2 (including)3.1.2 (including)

Potential Mitigations

References