CVE-2017-15293: Critical severity sap point of sale xpress server vulnerability
Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15293?
CVE-2017-15293 is considered a critical vulnerability due to the lack of authentication in SAP POS Xpress Server, allowing unauthorized access.
How do I fix CVE-2017-15293?
To mitigate CVE-2017-15293, ensure you apply the latest security patches provided by SAP for the affected versions of SAP POS Xpress Server.
What are the affected versions for CVE-2017-15293?
CVE-2017-15293 affects SAP Point Of Sale Xpress Server versions 1020 and 1030.
What are the potential attacks from CVE-2017-15293?
CVE-2017-15293 allows attackers to perform unauthorized file read and erase operations, daemon shutdown, and terminal read operations.
Is authentication required for operations affected by CVE-2017-15293?
No, CVE-2017-15293 indicates that no authentication is required for the affected operations in SAP POS Xpress Server.