Vulnerability was found in odata4j 0.7.0 which is allowing SQL injection in ExecuteJPQLQueryCommand.java NOTE: this product is apparently discontinued.
External References: https://groups.google.com/d/msg/odata4j-discuss/_lBwwXP30g0/Av6zkZMdBwAJ
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2016-11024