PT-2020-6876 · Abb · Esoms
Published
2020-02-17
·
Updated
2023-05-16
·
CVE-2019-19001
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ABB eSOMS versions 4.0 to 6.0.2
Description
The issue is related to the absence of the X-Frame-Options header in the HTTP response, which can potentially allow 'ClickJacking' attacks. This type of attack occurs when an attacker frames parts of the application on a malicious website, potentially revealing sensitive user information such as authentication credentials. An attacker, acting remotely, can exploit this issue to disclose authentication credentials and conduct clickjacking attacks.
Recommendations
For ABB eSOMS versions 4.0 to 6.0.2, consider configuring the X-Frame-Options header in the HTTP response to prevent 'ClickJacking' attacks. As a temporary workaround, restrict access to sensitive user information and authentication credentials until the issue is resolved.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Esoms