What are the best workarounds for using a SQL IN clause with instances of java.sql.PreparedStatement, which is not supported for multiple values due to SQL injection attack security issues: One ? ...
I'm not sure what you mean by the first option. I cannot perform your example using a PS. My query is comething like the following.. select * from employee e where e.status = 'A' and e.emp_id NOT in (?) The ? is dynamically assigned and can be any number of integers, which cannot be performed using PS. Raffi