Vulnerability Details CVE-2019-19089
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.7%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2019-19089
-
cpe:2.3:a:hitachienergy:esoms:4.0
-
cpe:2.3:a:hitachienergy:esoms:6.0
-
cpe:2.3:a:hitachienergy:esoms:6.0.2
-
cpe:2.3:a:hitachienergy:esoms:6.0.3