VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 26 of 39
  • CVE-2026-23620MedFeb 19, 2026
    risk 0.28cvss 4.3epss 0.00

    GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListServer.IsDBExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsDBExist. An authenticated user can supply an unrestricted…

  • CVE-2026-25562MedFeb 7, 2026
    risk 0.28cvss 4.3epss 0.00

    WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to…

  • CVE-2025-36225MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.

  • CVE-2025-9031MedSep 24, 2025
    risk 0.28cvss 4.3epss 0.00

    Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing. This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15.

  • CVE-2025-23182MedMay 22, 2025
    risk 0.28cvss 4.3epss 0.00

    CWE-203: Observable Discrepancy

  • CVE-2025-0361MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.00

    During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

  • CVE-2024-51477MedMar 29, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.

  • CVE-2024-45089MedJan 31, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an observable discrepancy.

  • CVE-2023-47159MedJan 27, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.

  • CVE-2025-24011MedJan 21, 2025
    risk 0.28cvss 5.3epss 0.01

    Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, it's possible to determine whether an account exists based on an analysis of response codes and timing of Umbraco management API responses.…

  • CVE-2024-21233MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via…

  • CVE-2024-21206MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-45231MedOct 8, 2024
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and…

  • CVE-2024-47129MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.00

    The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.

  • CVE-2024-41715MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.00

    The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.

  • CVE-2024-41952MedJul 31, 2024
    risk 0.28cvss 5.3epss 0.01

    Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password prompt even if the user doesn't…

  • CVE-2024-5697MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.

  • CVE-2024-5690MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.01

    By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

  • CVE-2023-6135MedDec 19, 2023
    risk 0.28cvss 4.3epss 0.01

    Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.

  • CVE-2023-23584MedDec 18, 2023
    risk 0.28cvss 4.3epss 0.01

    An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior…