CVE-2017-15293: SAP Point Of Sale Xpress Server

Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.

Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064.

Affected products

  • SAP Point Of Sale Xpress Server: version 1020 only; version 1030 only

Published 2017-10-16. Last modified 2026-06-17.