First published: Mon Mar 30 2020(Updated: )
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Odata4j | =0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-11024 is classified as high due to the potential for SQL injection attacks.
To fix CVE-2016-11024, it's recommended to upgrade to a version of Odata4j that is not affected, though the product is discontinued.
CVE-2016-11024 affects Odata4j version 0.7.0.
Yes, CVE-2016-11024 can lead to unauthorized access and exposure of sensitive data through SQL injection.
No, Odata4j appears to be a discontinued project, which means CVE-2016-11024 won't receive official patches.