Description
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-8728 | For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript. |
References
History
No history.
Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2024-08-05T02:09:39.266Z
Reserved: 2019-11-18T00:00:00.000Z
Link: CVE-2019-19089
No data.
Status : Modified
Published: 2020-04-02T20:15:14.423
Modified: 2024-11-21T04:34:10.793
Link: CVE-2019-19089
No data.
OpenCVE Enrichment
No data.
EUVD