VYPR
Medium severity6.8NVD Advisory· Published Feb 11, 2025· Updated Apr 15, 2026

CVE-2025-24875

CVE-2025-24875

Description

SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SAP Commerce sets authentication cookies with SameSite=None, weakening CSRF defenses in the Backoffice application.

The vulnerability identified in CVE-2025-24875 concerns the default cookie configuration in SAP Commerce. Specifically, the application sets certain cookies — including authentication cookies used by the SAP Commerce Backoffice — with the SameSite attribute configured to None (SameSite=None) [1]. This setting reduces the browser's built-in defense-in-depth against Cross-Site Request Forgery (CSRF) attacks because it allows the cookie to be sent in cross-site requests [1].

To exploit this weakness, an attacker would need to lure an authenticated Backoffice user into visiting a malicious site, which could then trigger unintended cross-site requests using the user's active session. The prerequisite is that the victim must be logged into SAP Commerce Backoffice; no additional authentication is required from the attacker beyond crafting the malicious page [1].

The impact is an increased risk of CSRF attacks that could perform state-changing operations on behalf of the authenticated user without their consent. While this does not directly lead to data breach, it undermines the security posture of the Backoffice by removing a modern browser-enforced CSRF mitigation [1].

SAP has addressed this issue as part of its regular Security Patch Day. Customers are advised to review and apply the relevant SAP Security Notes to correct the cookie configuration. No evidence of active exploitation in the wild has been reported at the time of publication [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.