Description
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
Remediation
References
https://groups.google.com/d/msg/odata4j-discuss/_lBwwXP30g0/Av6zkZMdBwAJ
Related Vulnerabilities
CVE-2017-12612 Vulnerability in maven package org.apache.spark:spark-core_2.10
CVE-2018-3719 Vulnerability in maven package org.webjars.npm:mixin-deep
CVE-2018-1002204 Vulnerability in npm package adm-zip
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.11
CVE-2019-1003032 Vulnerability in maven package org.jenkins-ci.plugins:email-ext