Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c74-ppcm-mjfw

Опубликовано: 11 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.

SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.

EPSS

Процентиль: 11%
0.00037
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.8
nvd
12 месяцев назад

SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.

EPSS

Процентиль: 11%
0.00037
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-352