Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/ - Issue Tracking, Vendor Advisory | |
References | () https://erpscan.io/advisories/erpscan-17-033-sap-pos-missing-authentication-xpressserver/ - | |
References | () https://erpscan.io/research/hacking-sap-pos/ - |
Information
Published : 2017-10-16 16:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-15295
Mitre link : CVE-2017-15295
CVE.ORG link : CVE-2017-15295
JSON object : View
Products Affected
sap
- point_of_sale_xpress_server
CWE
CWE-287
Improper Authentication