The Criteria API is parameter-safe for values, but Restrictions.sqlRestriction() embeds raw SQL and user-controlled property names reach unintended columns.
Concatenating user input into createQuery() HQL/JPQL bypasses Hibernate's parameter binding, exposing entity data through boolean logic and UNION-style object queries.
Hibernate's native-query APIs run raw backend SQL; concatenating user input into them yields full SQL injection including stacked queries and DBMS-specific functions.
We use cookies to enhance your experience. Learn more