{"api_version":"1","generated_at":"2026-07-23T09:27:20+00:00","cve":"CVE-2017-15293","urls":{"html":"https://cve.report/CVE-2017-15293","api":"https://cve.report/api/cve/CVE-2017-15293.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-15293","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-15293"},"summary":{"title":"CVE-2017-15293","description":"Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-10-16 16:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/","name":"https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"],"title":"SAP Security Patch Day – September 2017 | SAP Blogs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/100713","name":"http://www.securityfocus.com/bid/100713","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SAP Point of Sale (POS) Retail Xpress Server Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://erpscan.io/research/hacking-sap-pos/","name":"https://erpscan.io/research/hacking-sap-pos/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"How to buy MacBook for $1, or hacking SAP POS | SAP Cyber Security Solutions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://erpscan.io/advisories/erpscan-17-032-sap-pos-missing-authentication-xpressserver/","name":"https://erpscan.io/advisories/erpscan-17-032-sap-pos-missing-authentication-xpressserver/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[ERPSCAN-17-032] SAP POS Missing Authentication in XpressServer","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-15293","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15293","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"15293","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"point_of_sale_xpress_server","cpe6":"1020","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"15293","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"point_of_sale_xpress_server","cpe6":"1030","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T19:50:16.485Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://erpscan.io/advisories/erpscan-17-032-sap-pos-missing-authentication-xpressserver/"},{"name":"100713","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/100713"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://erpscan.io/research/hacking-sap-pos/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-07-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-12-10T17:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"https://erpscan.io/advisories/erpscan-17-032-sap-pos-missing-authentication-xpressserver/"},{"name":"100713","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/100713"},{"tags":["x_refsource_MISC"],"url":"https://erpscan.io/research/hacking-sap-pos/"},{"tags":["x_refsource_MISC"],"url":"https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-15293","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://erpscan.io/advisories/erpscan-17-032-sap-pos-missing-authentication-xpressserver/","refsource":"MISC","url":"https://erpscan.io/advisories/erpscan-17-032-sap-pos-missing-authentication-xpressserver/"},{"name":"100713","refsource":"BID","url":"http://www.securityfocus.com/bid/100713"},{"name":"https://erpscan.io/research/hacking-sap-pos/","refsource":"MISC","url":"https://erpscan.io/research/hacking-sap-pos/"},{"name":"https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/","refsource":"MISC","url":"https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2017-15293","datePublished":"2017-10-16T16:00:00.000Z","dateReserved":"2017-10-12T00:00:00.000Z","dateUpdated":"2024-08-05T19:50:16.485Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-10-16 16:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:point_of_sale_xpress_server:1020:*:*:*:*:*:*:*","matchCriteriaId":"4B5C1170-F8AD-4D69-976B-AC4A73095E2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:point_of_sale_xpress_server:1030:*:*:*:*:*:*:*","matchCriteriaId":"323D5C2D-1F41-4DBA-A718-43CE661951CC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"15293","Ordinal":"1","Title":"CVE-2017-15293","CVE":"CVE-2017-15293","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"15293","Ordinal":"1","NoteData":"Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064.","Type":"Description","Title":"CVE-2017-15293"},{"CveYear":"2017","CveId":"15293","Ordinal":"2","NoteData":"2017-10-16","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"15293","Ordinal":"3","NoteData":"2018-12-10","Type":"Other","Title":"Modified"}]}}}