CVE Explorer
CVE-2025-62728
SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized users/applications that are allowed to call directly the Thrift APIs. In most real-world deployments, HMS is accessible to only a handful of applications (e.g., Hiveserver2) thus the vulnerability is not exploitable. Moreover, the vulnerable code cannot be reached when metastore.try.direct.sql property is set
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"org.apache.hive:hive-standalone-metastore-server","product":"Apache Hive","vendor":"Apache Software Foundation","versions":[{"lessThan":"4.2.0","status":"affected","version":"4.1.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d65ffe242bc9de51806903099d71fef89eac2d79c4fabafa3e5abc03595f5871 · sha256:c93aa4d0392db1b4… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d65ffe242bc9de51806903099d71fef89eac2d79c4fabafa3e5abc03595f5871 · sha256:c93aa4d0392db1b4… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d65ffe242bc9de51806903099d71fef89eac2d79c4fabafa3e5abc03595f5871 · sha256:c93aa4d0392db1b4… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"http://www.openwall.com/lists/oss-security/2025/11/26/3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d65ffe242bc9de51806903099d71fef89eac2d79c4fabafa3e5abc03595f5871 · sha256:c93aa4d0392db1b4… · /containers/adp/0/references/0
{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/yj65dd8dmzgy8p3nv8zy33v8knzg9o7g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d65ffe242bc9de51806903099d71fef89eac2d79c4fabafa3e5abc03595f5871 · sha256:c93aa4d0392db1b4… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.