Common Weakness Enumeration

    CWE Definition / CWE-564

    CWE-564: SQL Injection: Hibernate

    Using Hibernate to execute a dynamic SQL statement built with user-controlled input can allow an attacker to modify the statement's meaning or to execute arbitrary SQL commands.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')