Description
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
Remediation
References
https://groups.google.com/d/msg/odata4j-discuss/_lBwwXP30g0/Av6zkZMdBwAJ
Related Vulnerabilities
CVE-2018-11693 Vulnerability in npm package node-sass
CVE-2022-2217 Vulnerability in npm package parse-url
CVE-2023-37582 Vulnerability in maven package org.apache.rocketmq:rocketmq-namesrv
CVE-2016-10650 Vulnerability in npm package ntfserver
CVE-2017-2601 Vulnerability in maven package org.jenkins-ci.main:jenkins-core