First published: Thu Apr 02 2020(Updated: )
For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachienergy Esoms | >=4.0<=6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19003 is a vulnerability found in ABB eSOMS versions 4.0 to 6.0.2 where the HTTPOnly flag is not set, allowing JavaScript to access the cookie contents and potentially enabling Cross Site Scripting (XSS) attacks.
CVE-2019-19003 affects ABB eSOMS versions 4.0 to 6.0.2 by not setting the HTTPOnly flag, which can allow JavaScript to access the cookie contents and potentially enable XSS attacks.
CVE-2019-19003 has a severity of 6.1 (medium).
To fix CVE-2019-19003, it is recommended to update ABB eSOMS to a version that includes the fix for this vulnerability.
More information about CVE-2019-19003 can be found in the ABB eSOMS security advisory document: [link](https://search.abb.com/library/Download.aspx?DocumentID=9AKK107492A9964&LanguageCode=en&DocumentPartId=&Action=Launch).