The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Jun 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks). | |
| Title | Missing HTTP Security Headers | |
| Weaknesses | CWE-693 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SICK AG
Published: 2025-06-12T14:15:07.492Z
Updated: 2025-10-06T07:23:25.144Z
Reserved: 2025-06-03T05:58:15.616Z
Link: CVE-2025-49193
Updated: 2025-06-12T14:33:47.471Z
Status : Awaiting Analysis
Published: 2025-06-12T15:15:39.433
Modified: 2025-06-12T16:06:20.180
Link: CVE-2025-49193
No data.