For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published: 2020-04-02T19:50:02

Updated: 2024-08-05T02:02:39.918Z

Reserved: 2019-11-15T00:00:00

Link: CVE-2019-19002

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-02T20:15:14.003

Modified: 2024-11-21T04:33:58.357

Link: CVE-2019-19002

cve-icon Redhat

No data.