VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 18 of 39
  • CVE-2019-25056MedJan 26, 2022
    risk 0.35cvss 5.3epss 0.01

    In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mechanism.

  • CVE-2021-20147MedJan 3, 2022
    risk 0.35cvss 5.3epss 0.07

    ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

  • CVE-2020-35398MedDec 23, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.

  • CVE-2021-44876MedDec 21, 2021
    risk 0.35cvss 5.3epss 0.01

    Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the…

  • CVE-2021-44875MedDec 21, 2021
    risk 0.35cvss 5.3epss 0.01

    Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the…

  • CVE-2021-44554MedDec 20, 2021
    risk 0.35cvss 5.3epss 0.01

    Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message returned; it can be presented in different…

  • CVE-2021-43398MedNov 4, 2021
    risk 0.35cvss 5.3epss 0.02

    Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. This might allow attackers to conduct…

  • CVE-2021-37151MedSep 1, 2021
    risk 0.35cvss 5.3epss 0.01

    CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate between a valid user and an invalid one…

  • CVE-2021-3642MedAug 5, 2021
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

  • CVE-2021-37606MedJul 30, 2021
    risk 0.35cvss 5.3epss 0.01

    Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attacker to infer collisions…

  • CVE-2021-20113MedJul 30, 2021
    risk 0.35cvss 5.3epss 0.01

    An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented with an ‘unknown email’ error. If an email is given that is registered with…

  • CVE-2021-32528MedJul 7, 2021
    risk 0.35cvss 5.3epss 0.01

    Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system information without permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-29687MedMay 20, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018

  • CVE-2021-1486MedMay 6, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability by sending authenticated requests to an…

  • CVE-2021-31866MedApr 28, 2021
    risk 0.35cvss 5.3epss 0.01

    Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.

  • CVE-2021-27583MedFeb 23, 2021
    risk 0.35cvss 5.3epss 0.01

    In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2020-28208MedJan 8, 2021
    risk 0.35cvss 5.3epss 0.11

    An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.

  • CVE-2019-12953MedDec 30, 2020
    risk 0.35cvss 5.3epss 0.01

    Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.

  • CVE-2020-35624MedDec 21, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.

  • CVE-2020-35480MedDec 18, 2020
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about…