Вам необходимо использовать PreparedStatement, как в:
public static void searchordernumber(int inputnum) {
try {
Connection connection = DriverManager.getConnection(url);
String sql = "SELECT * FROM orderTable WHERE ordernumber = ?";
PreparedStatement ps = connection.prepareStatement(sql));
ps.setInt(1, inputnum); // here's the magic
ResultSet rs = ps.executeQuery();
while (rs.next()) {
int id = rs.getInt(1); // assuming there's a column "id" of type INT
System.out.println("id=" + id);
}
connection.close();
} catch (SQLException e) {
System.out.println(e.getMessage());
}
}