Description
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
Remediation
References
https://groups.google.com/d/msg/odata4j-discuss/_lBwwXP30g0/Av6zkZMdBwAJ
Related Vulnerabilities
CVE-2021-39178 Vulnerability in npm package next
CVE-2020-2296 Vulnerability in maven package org.jenkins-ci.plugins:shared-objects
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-beans
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-common
CVE-2023-34455 Vulnerability in maven package org.xerial.snappy:snappy-java