Clickjacking Vulnerability in SAP Commerce Backoffice
CVE-2025-24874
6.8MEDIUM
Summary
SAP Commerce's Backoffice currently employs the deprecated X-FRAME-OPTIONS header to mitigate clickjacking attacks. While effective now, there are concerns that future browser updates may eliminate support for this header, replacing it with the frame-ancestors Content Security Policy directive. Such changes could leave systems vulnerable to clickjacking attempts, potentially allowing attackers to manipulate and gain access to sensitive information. Businesses using SAP Commerce should evaluate their security posture and prepare for this possible transition.
Affected Version(s)
SAP Commerce (Backoffice) HY_COM 2205
SAP Commerce (Backoffice) COM_CLOUD 2211
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved