Количество 3
Количество 3
CVE-2019-19089
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.
GHSA-wfq4-f757-c65c
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.
BDU:2023-03075
Уязвимость программного средства для управления производственными процессами ABB eSOMS, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-19089 For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript. | CVSS3: 6.1 | 0% Низкий | почти 6 лет назад | |
GHSA-wfq4-f757-c65c For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
BDU:2023-03075 Уязвимость программного средства для управления производственными процессами ABB eSOMS, позволяющая нарушителю выполнить произвольный код | CVSS3: 6.1 | 0% Низкий | почти 6 лет назад |
Уязвимостей на страницу