CVE-2016-11024: SQL Injection
Published Mar 30, 2020
·Updated
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
Affected Software
1 affected component
Odata4j Project Odata4j=0.7
Event History
Mar 30, 2020
CVE Published
via MITRE·07:41 PM
Data Sourced
via MITRE·07:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-11024?
The severity of CVE-2016-11024 is classified as high due to the potential for SQL injection attacks.
2
How do I fix CVE-2016-11024?
To fix CVE-2016-11024, it's recommended to upgrade to a version of Odata4j that is not affected, though the product is discontinued.
3
What software is affected by CVE-2016-11024?
CVE-2016-11024 affects Odata4j version 0.7.0.
4
Can CVE-2016-11024 lead to data exposure?
Yes, CVE-2016-11024 can lead to unauthorized access and exposure of sensitive data through SQL injection.
5
Is Odata4j still maintained in light of CVE-2016-11024?
No, Odata4j appears to be a discontinued project, which means CVE-2016-11024 won't receive official patches.