nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-19003 CVE-2019-19003
MEDIUM
ABB eSOMS: HTTPOnly flag not set
Record summary
CVE-2019-19003 has a selected CVSS score of 5.3 (medium).
Description
For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
eSOMSBrowse ABB / eSOMS | CVE List | 4.0 to 6.0.2 | affected |
References
2search.abb.comConfirmation
https://search.abb.com/library/Download.aspx?DocumentID=9AKK107492A9964&LanguageCode=en&DocumentPartId=&Action=Launch