this completely depends on your architecture and your components!
this is a general method working for any web application including J2EE ones:
when ever you have a usecase that client can enter a text that will be used as a part of a sql
check it to make sure it has not included any SQL.