First published: Tue Feb 11 2025(Updated: )
SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Commerce |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24875 is considered to have a medium severity due to its impact on CSRF protection.
To fix CVE-2025-24875, configure the SameSite attribute of affected cookies to 'Lax' or 'Strict' instead of 'None'.
CVE-2025-24875 affects SAP Commerce where certain cookies are set with the SameSite attribute as None.
The risk associated with CVE-2025-24875 includes potential CSRF attacks due to inadequate cookie protection.
A potential workaround for CVE-2025-24875 is to review and modify cookie settings in the application configuration to enhance security.