Vulnerability Description
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachienergy | Esoms | >= 4.0, <= 6.0.3 |
Related Weaknesses (CWE)
References
- https://search.abb.com/library/Download.aspx?DocumentID=9AKK107492A9964&LanguageVendor Advisory
- https://search.abb.com/library/Download.aspx?DocumentID=9AKK107492A9964&LanguageVendor Advisory
FAQ
What is CVE-2019-19089?
CVE-2019-19089 is a vulnerability with a CVSS score of 6.1 (MEDIUM). For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type ...
How severe is CVE-2019-19089?
CVE-2019-19089 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19089?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachienergy Esoms.