PT-2020-1843 · Abb · Abb Esoms

CVE-2019-19094

·

Published

2020-02-17

·

Updated

2023-05-16

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ABB eSOMS versions 3.9 to 6.0.3
Description The issue is related to a lack of input checks for SQL queries, which might allow an attacker to perform SQL injection attacks against the backend database. This could potentially be exploited by a remote attacker to execute arbitrary SQL queries on the vulnerable application's database.
Recommendations For ABB eSOMS versions 3.9 to 6.0.3, consider implementing input validation and sanitization for SQL queries to prevent SQL injection attacks. As a temporary workaround, restrict access to the backend database to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01117
CVE-2019-19094

Affected Products

Abb Esoms