0

Can I sql-inject jpl parameter set by setParameter? I mean, I know I can do it if I have something like this:

String nm = "'anything' or 'x'='x'--";
Query m = em.createQuery("SELECT p FROM Tbl p WHERE UPPER(p.name) = '" + nm + "'");

Can I do a similar thing with something like this?:

String nm = "'anything' or 'x'='x'--";
   Query m = em.createQuery("SELECT p FROM Tbl p WHERE UPPER(p.name) = :param").setParameter("param", nm.toUpperCase());
Lukas Eder
  • 211,314
  • 129
  • 689
  • 1,509
HtonS
  • 301
  • 4
  • 18

1 Answers1

1

It seems that it is sql-injection safe. I looked in sql queries log: potentially dangerous symbols are escaped in the resulting sql

HtonS
  • 301
  • 4
  • 18