String Formatting in SQL Construction
Using String.format(), concatenation, or StringBuilder to build SQL queries with variables.
SQL injection vulnerability where SQL uses concatenated or formatted variables executed via Statement without parameters, potentially allowing attackers to read or modify database data and execute dangerous operations.
Configuration changes required - see explanation below.
Configuration changes required - see explanation below.
Using String.format(), concatenation, or StringBuilder to build SQL queries with variables.
Sourcery automatically identifies sql injection from formatted sql string in jdbc statement and many other security issues in your codebase.