PT-2020-6876 · Abb · Esoms

Published

2020-02-17

·

Updated

2023-05-16

·

CVE-2019-19001

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ABB eSOMS versions 4.0 to 6.0.2
Description The issue is related to the absence of the X-Frame-Options header in the HTTP response, which can potentially allow 'ClickJacking' attacks. This type of attack occurs when an attacker frames parts of the application on a malicious website, potentially revealing sensitive user information such as authentication credentials. An attacker, acting remotely, can exploit this issue to disclose authentication credentials and conduct clickjacking attacks.
Recommendations For ABB eSOMS versions 4.0 to 6.0.2, consider configuring the X-Frame-Options header in the HTTP response to prevent 'ClickJacking' attacks. As a temporary workaround, restrict access to sensitive user information and authentication credentials until the issue is resolved.

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

BDU:2023-03051
CVE-2019-19001

Affected Products

Esoms