For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ABB
Published: 2020-04-02T19:46:45
Updated: 2024-08-05T02:09:38.942Z
Reserved: 2019-11-18T00:00:00
Link: CVE-2019-19090
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-02T20:15:14.737
Modified: 2024-11-21T04:34:10.913
Link: CVE-2019-19090
Redhat
No data.