XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.
https://github.com/xm-online/xm-commons/pull/62
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15558