SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP directive. Hence, clickjacking could become possible then, and lead to exposure and modification of sensitive information.
                
            References
                    Configurations
                    No configuration.
History
                    18 Feb 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
11 Feb 2025, 01:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-02-11 01:15
Updated : 2025-02-18 18:15
NVD link : CVE-2025-24874
Mitre link : CVE-2025-24874
CVE.ORG link : CVE-2025-24874
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-1021
                        
            Improper Restriction of Rendered UI Layers or Frames
