Authentication Flaw in SAP POS Xpress Server
CVE-2017-15295

9.8CRITICAL

Key Information:

Vendor
SAP
Vendor
CVE Published:
16 October 2017

Summary

The Xpress Server component of SAP POS is susceptible to a significant authentication bypass vulnerability, allowing unauthorized users to read, write, and delete files without requiring any form of authentication. This flaw poses a serious risk, as it can lead to exposure of sensitive data and potential manipulation of the system. SAP has issued Security Note 2520064 to address this issue, emphasizing the importance of applying necessary patches to mitigate associated risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.