Executive brief
SAP Business Object and the SAP Cloud SDK for AI Python are vulnerable to a flaw that allows authorized users to run unauthorized commands on the underlying server. This occurs when the 'Program Objects Execution' feature is enabled, allowing a user with basic scheduling rights to potentially take full control of the system, access sensitive data, or disrupt operations. The issue primarily affects Unix-based installations of the Adaptive Job Server.
Technical details
An OS command injection vulnerability (CWE-78) exists in SAP Business Object (Adaptive Job Server) versions 420 and 430, as well as the sap-ai-sdk-base Python package. The vulnerability is triggered when 'Program Objects Execution' is enabled. An authenticated attacker with scheduling privileges can exploit this via the BI Launchpad, Central Management Console, or custom applications using the public Java SDK to execute arbitrary commands on the host Unix system. This occurs due to improper neutralization of special elements used in OS commands. The attack vector is network-based with low complexity, requiring only low-level user privileges.
Affected products
- SAP sap-ai-sdk-base <= 3.3.0
- SAP Business Object (Adaptive Job Server) 420, 430
Timeline
- 2023-03-14: advisory: Initial publication of the advisory