web applications - Checkmarx's vulnerability scanner reports Java's HibernateTemplate.find() method to be vulnerable to SQLi attacks -
i'm developing java application using hibernate , spring framework. when scan project checkmarx's vulnerability scanner, reports several sql injection vulnerabilities in hibernatetemplate.find()
method.
how can fix this?. there secure alternative hibernatetemplate.find()
?
use hibernatetemplate.findbyexample(obj) or hibernatetemplate.findbycriteria() instead.
Comments
Post a Comment