Hibernate

Hibernate supports bound parameters, but HQL/JPQL assembled by string concatenation, native-SQL queries (createNativeQuery), and raw Restrictions.sqlRestriction fragments reintroduce SQL injection against the underlying JDBC backend. Attacker-controlled Criteria property or sort names are a related but distinct issue: Hibernate resolves them against mapped properties rather than splicing them into SQL, so they can expose unintended fields or ordering without being SQL injection.

Cookie Consent

We use cookies to enhance your experience. Learn more