Vulnerabilities > Hitachienergy > Esoms > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-01 CVE-2023-5514 Information Exposure Through an Error Message vulnerability in Hitachienergy Esoms
The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.
network
low complexity
hitachienergy CWE-209
5.3
2023-11-01 CVE-2023-5515 Unspecified vulnerability in Hitachienergy Esoms
The responses for web queries with certain parameters disclose internal path of resources.
network
low complexity
hitachienergy
5.3
2023-11-01 CVE-2023-5516 Unspecified vulnerability in Hitachienergy Esoms
Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the underlying technology and other sensitive information details.
network
low complexity
hitachienergy
5.3
2020-04-02 CVE-2019-19096 Insufficiently Protected Credentials vulnerability in Hitachienergy Esoms
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text.
local
low complexity
hitachienergy CWE-522
6.1
2020-04-02 CVE-2019-19095 Cross-site Scripting vulnerability in Hitachienergy Esoms
Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by storing malicious content in the database.
network
low complexity
hitachienergy CWE-79
5.4
2020-04-02 CVE-2019-19093 Weak Password Requirements vulnerability in Hitachienergy Esoms
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.
network
low complexity
hitachienergy CWE-521
6.5
2020-04-02 CVE-2019-19091 Information Exposure vulnerability in Hitachienergy Esoms
For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application.
network
low complexity
hitachienergy CWE-200
4.3
2020-04-02 CVE-2019-19089 Interpretation Conflict vulnerability in Hitachienergy Esoms
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared.
network
low complexity
hitachienergy CWE-436
6.1
2020-04-02 CVE-2019-19003 Cross-site Scripting vulnerability in Hitachienergy Esoms
For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set.
network
low complexity
hitachienergy CWE-79
6.1
2020-04-02 CVE-2019-19002 Cross-site Scripting vulnerability in Hitachienergy Esoms
For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server.
network
low complexity
hitachienergy CWE-79
5.4