odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-11024.json"