CVE-2025-24874
SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP directive. Hence, clickjacking could become possible then, and lead to exposure and modification of sensitive information.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.32%
- CWE
- CWE-1021
- Published
- 2025-02-11
- Last modified
- 2026-03-12
Affected products
- SAP_SE SAP Commerce (Backoffice)
- SAP_SE SAP Commerce (Backoffice)
Weakness type
Related vulnerabilities
- CVE-2026-87995 — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
- CVE-2026-87538 — Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had...
- CVE-2026-87655 — Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87486 — Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed...
- CVE-2026-75548 — Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames
- CVE-2026-18534 — Address bar spoofing risk in affected iOS versions of Arc Search
- CVE-2026-44762 — Security Misconfiguration in SAP Data Services Management Console
- CVE-2026-70608 — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path