VYPR
Medium severity5.3NVD Advisory· Published Apr 2, 2020· Updated Jun 17, 2026

CVE-2019-19003

CVE-2019-19003

Description

For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.

Affected products

3
  • Abb/eSOMScpe-rescue2 versions
    4.0 to 6.0.2+ 1 more
    • (no CPE)range: 4.0 to 6.0.2
    • (no CPE)range: 4.0 - 6.0.2
  • cpe:2.3:a:hitachienergy:esoms:*:*:*:*:*:*:*:*
    Range: >=4.0,<=6.0.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.