GHSA-xxhh-59gh-6ffx

Suggest an improvement
Source
https://github.com/advisories/GHSA-xxhh-59gh-6ffx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-xxhh-59gh-6ffx/GHSA-xxhh-59gh-6ffx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xxhh-59gh-6ffx
Aliases
Published
2023-03-14T06:30:16Z
Modified
2026-06-09T21:11:21Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SAP Cloud SDK for AI Python has OS Command Injection when Program Objects Execution is Enabled
Details

SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK. Programs could impact the confidentiality, integrity and availability of the system.

Database specific
{
    "cwe_ids":  [
        "CWE-74",
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-09T20:46:30Z",
    "nvd_published_at":  "2023-03-14T05:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

PyPI / sap-ai-sdk-base

Package

Name
sap-ai-sdk-base
View open source insights on deps.dev
Purl
pkg:pypi/sap-ai-sdk-base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.3.0

Affected versions

3.*
3.1.2
3.1.3
3.1.6
3.2.0
3.2.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-xxhh-59gh-6ffx/GHSA-xxhh-59gh-6ffx.json"