{"id":"CVE-2016-6652","aliases":["GHSA-xr4v-28rm-pvgw"],"url":"https://o3.security/vulnerability/CVE-2016-6652","summary":"Improper Neutralization of Special Elements used in an SQL Command  Pivotal Spring Data JPA","details":"SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.","published":"2016-10-05T16:59:04.757Z","modified":"2026-07-08T12:53:07.999620Z","cvss":{"score":5.6,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework.data:spring-data-jpa","fixedVersion":"1.9.6"},{"ecosystem":"Maven","name":"org.springframework.data:spring-data-jpa","fixedVersion":"1.10.4"}],"fix":null,"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/93276"},{"type":"ADVISORY","url":"https://jira.spring.io/browse/DATAJPA-965"},{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2016-6652"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201701-01"},{"type":"FIX","url":"https://github.com/spring-projects/spring-data-jpa/commit/b8e7fe"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:53:07.999620Z"}}