VendorsHitachi Energyesomsany version
Vulnerabilities

Hitachi Energy eSOMS (Electronic Shift Operations Management System) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2019-19094
ABB eSOMS: SQL injection vulnerability
Published 2020-04-02 · Modified
7.6EPSS 0.009
CVE-2021-35527
Password Autocomplete Vulnerability in Hitachi ABB Power Grids eSOMS Application
Published 2021-07-14 · Modified
7.5EPSS 0.010
CVE-2021-26845
eSOMS Report Function Vulnerability
Published 2021-06-14 · Modified
7.5EPSS 0.009
CVE-2019-19097
ABB eSOMS: SSL medium strength Cipher Suites
Published 2020-04-02 · Modified
7.5EPSS 0.007
CVE-2019-19001
eSOMS X-FrameOption
Published 2020-04-02 · Modified
6.5EPSS 0.016
CVE-2019-19000
eSOMS Cachecontrol (Pragma) HTTP Header
Published 2020-04-02 · Modified
6.5EPSS 0.011
CVE-2019-19093
ABB eSOMS: Password complexity issue
Published 2020-04-02 · Modified
6.5EPSS 0.009
CVE-2019-19002
ABB eSOMS X-XSS-Protection not enabled
Published 2020-04-02 · Modified
6.3EPSS 0.008
CVE-2019-19089
eSOMS: X-Content-Type-Options Header Missing
Published 2020-04-02 · Modified
6.1EPSS 0.011
CVE-2019-19003
ABB eSOMS: HTTPOnly flag not set
Published 2020-04-02 · Modified
6.1EPSS 0.008
CVE-2019-19096
ABB eSOMS: REDIS clear text credentials
Published 2020-04-02 · Modified
6.1EPSS 0.003
CVE-2019-19095
ABB eSOMS: Stored XSS vulnerability
Published 2020-04-02 · Modified
5.4EPSS 0.006
CVE-2023-5514
The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.
Published 2023-11-01 · Modified
5.3EPSS 0.004
CVE-2023-5515
The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure of the application and to further plot attacks against web servers and deployed web applications.
Published 2023-11-01 · Modified
5.3EPSS 0.004
CVE-2023-5516
Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the underlying technology and other sensitive information details. The website unintentionally reveals sensitive information including technical details like version Info, endpoints, backend server, Internal IP. etc., which can potentially expose additional attack surface containing other interesting vulnerabilities.
Published 2023-11-01 · Modified
5.3EPSS 0.004
CVE-2019-19091
ABB eSOMS: HTTP response information leakage
Published 2020-04-02 · Modified
4.3EPSS 0.008
CVE-2019-19092
ABB eSOMS: Viewstate without MAC Signature
Published 2020-04-02 · Modified
3.5EPSS 0.008
CVE-2019-19090
ABB eSOMS: Secure Flag not set
Published 2020-04-02 · Modified
3.5EPSS 0.005