For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.
Weaknesses in this category are typically introduced during the configuration of the software.
The product does not encrypt sensitive or critical information before storage or transmission.