René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

126 lines
3.6 KiB
JSON

{
"id": "CVE-2017-15293",
"sourceIdentifier": "cve@mitre.org",
"published": "2017-10-16T16:29:00.917",
"lastModified": "2019-10-03T00:03:26.223",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064."
},
{
"lang": "es",
"value": "Xpress Server en SAP POS no requiere autenticaci\u00f3n para las operaciones de lectura y borrado de archivos, apagado del demonio, operaciones de lectura del terminal, o ciertos ataques sobre credenciales. Esto corresponde con SAP Security Note 2520064."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 10.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:point_of_sale_xpress_server:1020:*:*:*:*:*:*:*",
"matchCriteriaId": "4B5C1170-F8AD-4D69-976B-AC4A73095E2A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:point_of_sale_xpress_server:1030:*:*:*:*:*:*:*",
"matchCriteriaId": "323D5C2D-1F41-4DBA-A718-43CE661951CC"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/100713",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/",
"source": "cve@mitre.org",
"tags": [
"Issue Tracking",
"Vendor Advisory"
]
},
{
"url": "https://erpscan.io/advisories/erpscan-17-032-sap-pos-missing-authentication-xpressserver/",
"source": "cve@mitre.org"
},
{
"url": "https://erpscan.io/research/hacking-sap-pos/",
"source": "cve@mitre.org"
}
]
}