VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 33 of 39
  • CVE-2021-1031LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional…

  • CVE-2021-1018LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2021-1015LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges…

  • CVE-2021-0995LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional…

  • CVE-2021-0990LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2021-0989LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…

  • CVE-2021-0988LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no…

  • CVE-2021-0987LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…

  • CVE-2020-24512LowJun 9, 2021
    risk 0.21cvss 3.3epss 0.00

    Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2025-46720LowMay 5, 2025
    risk 0.20cvss 3.1epss 0.00

    Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These filters can be used as an oracle to probe the existence or value of…

  • CVE-2024-21251LowOct 15, 2024
    risk 0.20cvss 3.1epss 0.00

    Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network…

  • CVE-2022-29185MedMay 20, 2022
    risk 0.20cvss 4.2epss 0.01

    totp-rs is a Rust library that permits the creation of 2FA authentification tokens per time-based one-time password (TOTP). Prior to version 1.1.0, token comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the…

  • CVE-2020-9690MedJul 29, 2020
    risk 0.20cvss 4.2epss 0.02

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.

  • CVE-2019-2818LowJul 23, 2019
    risk 0.20cvss 3.1epss 0.02

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 11.0.3 and 12.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…

  • CVE-2026-58445LowAug 13, 2026
    risk 0.18cvss 2.7epss 0.00

    Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

  • CVE-2025-65185LowDec 17, 2025
    risk 0.18cvss 2.8epss 0.00

    There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an OTP code and new password then reviewing application responses.

  • CVE-2025-68164LowDec 16, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test

  • CVE-2026-47011LowJul 21, 2026
    risk 0.17cvss 2.6epss 0.00

    Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel…

  • CVE-2025-1396LowSep 26, 2025
    risk 0.17cvss 3.7epss 0.00

    A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system returns a distinct "User does not exist" error message to the login form, regardless of the validate_username setting. This behavior…

  • CVE-2025-51586LowSep 8, 2025
    risk 0.17cvss 3.7epss 0.01

    An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.