Or you can use the utility method: "org.apache.commons.lang.StringEscapeUtils.escapeSql(java.lang.String str)" to prevent sql-injection from happening.
String sanitation is always be best policy to prevent sql-injection or cross-site-scripting attacks.