CVE-2017-15295: SAP Point Of Sale Xpress Server

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.

Affected products

  • SAP Point Of Sale Xpress Server: version 1020 only; version 1030 only

Published 2017-10-16. Last modified 2026-06-17.