Advisory
A note with CVSS 6.8 for component CEC-SCC-CDM-BO-FRW was released by SAP on 11.02.2025. The correction/advisory 3559510 was described with "[CVE-2025-24874] Missing Defense in Depth Against Clickjacking in SAP Commerce (Backoffice)" and affects the system type SAP Commerce Cloud.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is clickjacking within SAP Commerce Cloud.
Risk specification
SAP Commerce (Backoffice) allows an unauthenticated attacker to execute clickjacking attacks due to the deprecation of the X-FRAME-OPTIONS header in newer browsers, potentially leading to the exposure and modification of sensitive information.Solution
The frame-ancestors 'self' directive has been added to the default value of the backoffice.response.header.Content-Security-Policy configuration item, mitigating clickjacking attacks. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Follow Backoffice Framework Security to manually add frame-ancestors with a desired value into the CSP.".
- 5.4 [CVE-2021-21444] Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)
- 5.4 Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration
- 5.4 Clickjacking vulnerability in SAP Process Integration (Integration Builder Framework)
- 4.6 Clickjacking vulnerability in Runtime Workbench of SAP Process Integration
- 4.3 Whitelist service for Clickjacking Framing Protection in AS ABAP