|
223351
|
5.4 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by storing malicious content in the database.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19095
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223352
|
7.6 |
HIGH
Network
|
hitachienergy
|
esoms
|
Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.
|
CWE-89
SQL Injection
|
CVE-2019-19094
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223353
|
6.5 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.
|
CWE-521
Weak Password Requirements
|
CVE-2019-19093
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223354
|
3.5 |
LOW
Network
|
hitachienergy
|
esoms
|
ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19092
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223355
|
4.3 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.
|
CWE-200
Information Exposure
|
CVE-2019-19091
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223356
|
3.5 |
LOW
Network
|
hitachienergy
|
esoms
|
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-19090
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223357
|
6.1 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type…
|
CWE-94 CWE-436
Code Injection Interpretation Conflict
|
CVE-2019-19089
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223358
|
8.1 |
HIGH
Network
|
tribalgroup
|
sits\
|
An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its default configuration, related to unencrypted communications sent by the client e…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-19127
|
2024-11-21 13:34 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223359
|
7.2 |
HIGH
Network
|
zohocorp
|
manageengine_assetexplorer
|
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows a…
|
CWE-78
OS Command
|
CVE-2019-19034
|
2024-11-21 13:34 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223360
|
7.5 |
HIGH
Network
|
xmidt
|
cjwt
|
Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted accidental JWT acceptance.
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2019-19324
|
2024-11-21 13:34 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|