SAP Commerce, by default, sets certain cookies with the...
Moderate severity
Unreviewed
Published
Feb 11, 2025
to the GitHub Advisory Database
•
Updated Feb 11, 2025
Description
Published by the National Vulnerability Database
Feb 11, 2025
Published to the GitHub Advisory Database
Feb 11, 2025
Last updated
Feb 11, 2025
SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.
References