Use of Web Browser Cache Containing Sensitive Information in eSOMS - CVE-2019-19000

 

Use of Web Browser Cache Containing Sensitive Information in eSOMS - CVE-2019-19000

Published: March 13, 2020


Vulnerability identifier: #VU26059
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-19000
CWE-ID: CWE-525
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: ABB
Affected software:
eSOMS

Detailed vulnerability description

The vulnerability allows a remote attacker to gain access to sensitive information on the target system.

The vulnerability exists due to the X-XSS-Protection HTTP response header is not set in responses from the web server. This can potentially allow browsers and proxies to cache sensitive information and might increase the risk of cross-site scripting attack. A remote attacker can gain access to sensitive information.

How to mitigate CVE-2019-19000

Install updates from vendor's website.

Sources