Description
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
Remediation
References
https://groups.google.com/d/msg/odata4j-discuss/_lBwwXP30g0/Av6zkZMdBwAJ
Related Vulnerabilities
CVE-2021-21193 Vulnerability in npm package electron
CVE-2012-0394 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2020-28276 Vulnerability in npm package deep-set
CVE-2022-43413 Vulnerability in maven package org.jenkins-ci.plugins:job-import-plugin
CVE-2020-11023 Vulnerability in maven package org.webjars:jquery