CWE-203
Observable Discrepancy
Description
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-189
CVEs mapped to this weakness (762)
page 22 of 39| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-42343 | Med | 0.34 | 5.3 | 0.00 | Sep 8, 2024 | Loway - CWE-204: Observable Response Discrepancy | ||
| CVE-2024-38431 | Med | 0.34 | 5.3 | 0.00 | Jul 30, 2024 | Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy | ||
| CVE-2024-36996 | Med | 0.34 | 5.3 | 0.00 | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user exists on the instance by deciphering the error response that they would likely receive from the instance… | ||
| CVE-2024-38322 | Med | 0.34 | 5.3 | 0.00 | Jun 28, 2024 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869. | ||
| CVE-2024-38465 | Med | 0.34 | 5.3 | 0.00 | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error. | ||
| CVE-2024-31878 | Med | 0.34 | 5.3 | 0.00 | Jun 7, 2024 | IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used by a malicious actor to gather information about SST users that can be targeted in further attacks. IBM X-Force ID: 287538. | ||
| CVE-2023-27283 | Med | 0.34 | 5.3 | 0.00 | May 4, 2024 | IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545. | ||
| CVE-2021-20556 | Med | 0.34 | 5.3 | 0.00 | May 3, 2024 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181. | ||
| CVE-2024-30176 | Med | 0.34 | 5.3 | 0.00 | May 1, 2024 | In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets. | ||
| CVE-2024-25651 | Med | 0.34 | 5.3 | 0.00 | Mar 14, 2024 | User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint. | ||
| CVE-2023-38362 | Med | 0.34 | 5.3 | 0.00 | Mar 4, 2024 | IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814. | ||
| CVE-2024-25146 | Med | 0.34 | 5.3 | 0.01 | Feb 8, 2024 | Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have… | ||
| CVE-2024-0564 | Med | 0.34 | 5.3 | 0.01 | Jan 30, 2024 | A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of… | ||
| CVE-2024-22647 | Med | 0.34 | 5.3 | 0.01 | Jan 30, 2024 | An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames. | ||
| CVE-2023-43623 | Med | 0.34 | 5.3 | 0.01 | Oct 10, 2023 | A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.3), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.3), Mendix Forgot Password… | ||
| CVE-2023-4095 | Med | 0.34 | 5.3 | 0.00 | Sep 19, 2023 | User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to obtain a list of registered users in the application, obtaining the necessary information to perform more complex attacks on the platform. | ||
| CVE-2023-3221 | Med | 0.34 | 5.3 | 0.00 | Sep 4, 2023 | User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database. | ||
| CVE-2023-3462 | Med | 0.34 | 5.3 | 0.01 | Jul 31, 2023 | HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This… | ||
| CVE-2023-37217 | Med | 0.34 | 5.3 | 0.00 | Jul 30, 2023 | Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy | ||
| CVE-2023-3897 | Med | 0.34 | 4.8 | 0.03 | Jul 25, 2023 | Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message. This issue affects SureMDM On-premise: 6.31 and below version |
- risk 0.34cvss 5.3epss 0.00
Loway - CWE-204: Observable Response Discrepancy
- risk 0.34cvss 5.3epss 0.00
Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy
- risk 0.34cvss 5.3epss 0.00
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user exists on the instance by deciphering the error response that they would likely receive from the instance…
- risk 0.34cvss 5.3epss 0.00
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869.
- risk 0.34cvss 5.3epss 0.00
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.
- risk 0.34cvss 5.3epss 0.00
IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used by a malicious actor to gather information about SST users that can be targeted in further attacks. IBM X-Force ID: 287538.
- risk 0.34cvss 5.3epss 0.00
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.
- risk 0.34cvss 5.3epss 0.00
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
- risk 0.34cvss 5.3epss 0.00
In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.
- risk 0.34cvss 5.3epss 0.00
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint.
- risk 0.34cvss 5.3epss 0.00
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.
- risk 0.34cvss 5.3epss 0.01
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have…
- risk 0.34cvss 5.3epss 0.01
A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of…
- risk 0.34cvss 5.3epss 0.01
An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames.
- risk 0.34cvss 5.3epss 0.01
A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.3), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.3), Mendix Forgot Password…
- risk 0.34cvss 5.3epss 0.00
User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to obtain a list of registered users in the application, obtaining the necessary information to perform more complex attacks on the platform.
- risk 0.34cvss 5.3epss 0.00
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.
- risk 0.34cvss 5.3epss 0.01
HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This…
- risk 0.34cvss 5.3epss 0.00
Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy
- risk 0.34cvss 4.8epss 0.03
Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message. This issue affects SureMDM On-premise: 6.31 and below version