CVE-2019-19000

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
02/04/2020
Last modified:
16/05/2023

Description

For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hitachienergy:esoms:*:*:*:*:*:*:*:* 4.0 (including) 6.0.3 (including)