sap-commerce-cloud
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyscripts/query-items.sh
LOWAnomalyLOW
scripts/query-items.sh
No clear malicious behavior is present. The script is an administrative HAC query client, but it carries meaningful operational security risk because it submits generated Groovy to a privileged scripting console, only weakly validates the query, may mishandle special input during Groovy embedding, stores credentials temporarily, and offers an insecure TLS mode. Use only with trusted URLs, authorized HAC credentials, and strict server-side permissions; robustly parse and enforce read-only queries and avoid embedding untrusted text in source code.
Confidence: 94%Severity: 58%
Audit Metadata