NA - CVE-2025-24874 - SAP Commerce (Backoffice) uses the deprecated...
SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers...
NA - CVE-2025-24875 - SAP Commerce, by default, sets certain cookies...
SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying...
NA - CVE-2025-24876 - The SAP Approuter Node.js package version...
The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting...
NA - CVE-2025-25241 - Due to a missing authorization check, an...
Due to a missing authorization check, an attacker who is logged in to application can view/ delete ?My Overtime Requests? which could allow the attacker to access employee information. This leads...
NA - CVE-2025-25243 - SAP Supplier Relationship Management (Master...
SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without...