VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 23 of 39
  • CVE-2023-35698MedJul 10, 2023
    risk 0.34cvss 5.3epss 0.01

    Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.

  • CVE-2023-3529MedJul 6, 2023
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unknown part of the file /LandingPages/api/otp/send?id=[ID][ampersand]method=sms of the component OTP URI Interface. The manipulation leads to information…

  • CVE-2023-3336MedJul 5, 2023
    risk 0.34cvss 5.3epss 0.01

    TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users.…

  • CVE-2023-37305MedJun 30, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.

  • CVE-2023-34344MedJun 12, 2023
    risk 0.34cvss 5.3epss 0.00

    AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username, which may lead to information disclosure.

  • CVE-2023-33518MedJun 5, 2023
    risk 0.34cvss 5.3epss 0.00

    emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request.

  • CVE-2023-31186MedMay 30, 2023
    risk 0.34cvss 5.3epss 0.00

    Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy

  • CVE-2023-28015MedMay 23, 2023
    risk 0.34cvss 5.3epss 0.00

    The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability.   During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not.  The attacker could use this information to focus a…

  • CVE-2023-28412MedMay 22, 2023
    risk 0.34cvss 5.3epss 0.00

    When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.

  • CVE-2023-27464MedApr 11, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.1.1). The affected versions of the…

  • CVE-2022-42288MedJan 13, 2023
    risk 0.34cvss 5.3epss 0.00

    NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.

  • CVE-2022-45163MedNov 18, 2022
    risk 0.34cvss 5.3epss 0.01

    An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid.…

  • CVE-2021-45925MedOct 24, 2022
    risk 0.34cvss 5.3epss 0.01

    Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

  • CVE-2022-43412MedOct 19, 2022
    risk 0.34cvss 5.3epss 0.01

    Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2022-32425MedJul 14, 2022
    risk 0.34cvss 5.3epss 0.01

    The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.

  • CVE-2021-39021MedFeb 2, 2022
    risk 0.34cvss 5.3epss 0.01

    IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration. IBM X-Force ID: 213856.

  • CVE-2020-4699MedOct 12, 2020
    risk 0.34cvss 5.3epss 0.00

    IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186947.

  • CVE-2020-4661MedOct 12, 2020
    risk 0.34cvss 5.3epss 0.00

    IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186142.

  • CVE-2020-4660MedOct 12, 2020
    risk 0.34cvss 5.3epss 0.00

    IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186140.

  • CVE-2019-16782MedDec 18, 2019
    risk 0.34cvss 6.3epss 0.04

    There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually…