Multiple vulnerabilities in SAP Commerce



Risk Low
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2025-24874
CVE-2025-24875
CWE-ID CWE-16
CWE-1275
Exploitation vector Network
Public exploit N/A
Vulnerable software
Commerce Backoffice
Web applications / E-Commerce systems

SAP Commerce
Web applications / E-Commerce systems

Vendor SAP

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Configuration

EUVDB-ID: #VU103906

Risk: Low

CVSSv4.0: 0.5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-24874

CWE-ID: CWE-16 - Configuration

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to usage of X-Frame-Options HTTP header instead of frame-ancestors CSP directive, which does not provide sufficient protection against clickjacking attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Commerce Backoffice: 2205 - 2211

CPE2.3 External links

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/february-2025.html
https://me.sap.com/notes/3559510


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Sensitive cookie with improper SameSite attribute

EUVDB-ID: #VU103904

Risk: Low

CVSSv4.0: 0.5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-24875

CWE-ID: CWE-1275 - Sensitive Cookie with Improper SameSite Attribute

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass security features.

The vulnerability exists due to application sets certain cookies with the SameSite attribute configured to None. A remote attacker can bypass implemented security features.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

SAP Commerce: 2205 - 2211

CPE2.3 External links

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/february-2025.html
https://me.sap.com/notes/3555364


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###