← Back to CVE List

CVE-2019-19001

Published: 2020-04-02T20:15Z
Last Modified: 2024-11-21T04:33Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt