For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.
Weaknesses in this category are typically introduced during the configuration of the software.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.