CVE-2017-15295: Critical severity sap point of sale xpress server vulnerability
Published Oct 16, 2017
·Updated
Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.
Affected Software
2 affected components
SAP Point Of Sale Xpress Server=1020
SAP Point Of Sale Xpress Server=1030
Event History
Oct 16, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15295?
CVE-2017-15295 is considered a critical vulnerability due to its potential to allow unauthorized access to file operations.
2
How do I fix CVE-2017-15295?
To resolve CVE-2017-15295, it is recommended to apply security patches provided in SAP Security Note 2520064.
3
What types of access does CVE-2017-15295 allow?
CVE-2017-15295 allows unauthenticated read, write, and delete access to files in the SAP Xpress Server.
4
Which versions of SAP Point Of Sale Xpress Server are affected by CVE-2017-15295?
CVE-2017-15295 affects SAP Point Of Sale Xpress Server versions 1020 and 1030.
5
Is authentication required for file access in CVE-2017-15295?
CVE-2017-15295 does not require authentication for read/write/delete file access, making it a significant security risk.