VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 27 of 39
  • CVE-2023-38871MedSep 28, 2023
    risk 0.28cvss 5.3epss 0.01

    The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differently when a user or email address is valid, and when it's not. This may allow an attacker to…

  • CVE-2023-22359MedJun 26, 2023
    risk 0.28cvss 4.3epss 0.01

    User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.

  • CVE-2022-24695MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, unique Bluetooth MAC…

  • CVE-2023-24598MedMay 29, 2023
    risk 0.28cvss 4.3epss 0.01

    OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.

  • CVE-2023-1540MedMar 21, 2023
    risk 0.28cvss 5.3epss 0.01

    Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

  • CVE-2023-1538MedMar 21, 2023
    risk 0.28cvss 5.3epss 0.01

    Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

  • CVE-2022-4025MedJan 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)

  • CVE-2022-26382MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects…

  • CVE-2020-35473MedNov 8, 2022
    risk 0.28cvss 4.3epss 0.00

    An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.2, and extended scan response in Bluetooth Core Specifications 5.0 through 5.2, may be used to identify devices using Resolvable Private…

  • CVE-2022-43411MedOct 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2021-36201MedOct 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.

  • CVE-2022-32218MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to the actionLinkHandler method was found to allow Message ID Enumeration with Regex MongoDB queries.

  • CVE-2022-36105MedSep 13, 2022
    risk 0.28cvss 5.3epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that observing response time during user authentication (backend and frontend) can be used to distinguish between existing and non-existing user accounts. Extension…

  • CVE-2022-36885MedJul 27, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

  • CVE-2022-32273MedJun 8, 2022
    risk 0.28cvss 4.3epss 0.01

    As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.

  • CVE-2022-0569MedFeb 14, 2022
    risk 0.28cvss 5.3epss 0.01

    Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.

  • CVE-2022-21659MedJan 31, 2022
    risk 0.28cvss 5.3epss 0.01

    Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accounts by timing the response…

  • CVE-2022-23106MedJan 12, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

  • CVE-2021-37968MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-20376MedOct 7, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.