First published: Thu Apr 02 2020(Updated: )
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachienergy Esoms | >=4.0<=6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-19089.
CVE-2019-19089 has a severity of 6.1 (medium).
The affected software for CVE-2019-19089 is ABB eSOMS versions 4.0 to 6.0.3.
The potential impact of CVE-2019-19089 is unauthorized code execution via text interpretation.
To fix CVE-2019-19089, update to a version of ABB eSOMS that includes the X-Content-Type-Options Header in the HTTP response.