← back
CVE-2025-24875mediumCWE-352

SameSite Defense in Depth not applied for some cookies in SAP Commerce

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.8epss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected products
SAP_SE · SAP Commerce