Description

SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP directive. Hence, clickjacking could become possible then, and lead to exposure and modification of sensitive information.

INFO

Published Date :

2025-02-11T00:37:22.842Z

Last Modified :

2025-02-18T18:05:26.373Z

Source :

sap
AFFECTED PRODUCTS

The following products are affected by CVE-2025-24874 vulnerability.

Vendors Products
Sap
  • Commerce Backoffice
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-24874.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact