SQL injections

User-defined function DLLs can call any SQL statements that developers write, so you must adhere to secure SQL coding practices when writing SQL to be used by the user-defined function code.