I am currently working on refactoring existing code as per veracode standards. I have a piece of code where Order By clause is dynamically created based on user input. In veracode it suggest to use Named Parameter but that is not possible. Below is code base. Please help with possible solution.
orderClauses.append("ORDER BY ");
orderClauses.append(report.getSortColumn1()));
orderClauses.append(" ");
orderClauses.append(report.getSortOrder1());