For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.
Weaknesses in this category are typically introduced during the configuration of the software.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.