CSRF Vulnerability in SAP Commerce Authentication Cookies
CVE-2025-24875

6.8MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
11 February 2025

Summary

SAP Commerce has a vulnerability where authentication cookies are set with the SameSite attribute configured to None. This configuration may reduce the effectiveness of defense-in-depth strategies against CSRF attacks and can lead to potential compatibility issues in the future. Organizations using affected versions of SAP Commerce should review their cookie configurations and implement appropriate security measures to mitigate risks associated with CSRF.

Affected Version(s)

SAP Commerce HY_COM 2205

SAP Commerce COM_CLOUD 2211

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.