PT-2020-1843 · Abb · Abb Esoms

Published

2020-02-17

·

Updated

2023-05-16

·

CVE-2019-19094

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ABB eSOMS versions 3.9 to 6.0.3
Description The issue is related to a lack of input checks for SQL queries, which might allow an attacker to perform SQL injection attacks against the backend database. This could potentially be exploited by a remote attacker to execute arbitrary SQL queries on the vulnerable application's database.
Recommendations For ABB eSOMS versions 3.9 to 6.0.3, consider implementing input validation and sanitization for SQL queries to prevent SQL injection attacks. As a temporary workaround, restrict access to the backend database to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2020-01117
CVE-2019-19094

Affected Products

Abb Esoms