Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Point_of_sale_xpress_server | Sap | 1020 (including) | 1020 (including) |
Point_of_sale_xpress_server | Sap | 1030 (including) | 1030 (including) |