VYPR

CWE-204

Observable Response Discrepancy

BaseIncomplete

Description

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-331 · CAPEC-332 · CAPEC-541 · CAPEC-580

CVEs mapped to this weakness (179)

page 4 of 9
  • CVE-2025-0163MedJun 11, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.

  • CVE-2024-47057MedMay 28, 2025
    risk 0.34cvss 5.3epss 0.00

    SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration…

  • CVE-2025-3939MedMay 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara…

  • CVE-2024-51447MedMay 13, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an observable response discrepancy vulnerability when validating usernames. This could allow an…

  • CVE-2025-24342MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernames via multiple crafted HTTP requests.

  • CVE-2025-30280MedApr 8, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions < V10.12.16), Mendix Runtime V10.18 (All versions < V10.18.5), Mendix Runtime V10.6 (All versions < V10.6.22), Mendix Runtime V8 (All versions < V8.18.35),…

  • CVE-2024-56476MedApr 2, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.

  • CVE-2024-55198MedMar 13, 2025
    risk 0.34cvss 5.3epss 0.00

    User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.

  • CVE-2025-23193MedFeb 11, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no…

  • CVE-2023-37413MedJan 29, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.

  • CVE-2024-35114MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.

  • CVE-2025-0693MedJan 23, 2025
    risk 0.34cvss 5.3epss 0.00

    Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.

  • CVE-2024-8651MedSep 19, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch…

  • CVE-2024-34336MedSep 12, 2024
    risk 0.34cvss 5.3epss 0.00

    User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.

  • CVE-2023-49069MedSep 10, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.11 only if the basic authentication mechanism is used by the application),…

  • CVE-2024-42343MedSep 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Loway - CWE-204: Observable Response Discrepancy

  • CVE-2024-38431MedJul 30, 2024
    risk 0.34cvss 5.3epss 0.00

    Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy

  • CVE-2023-33859MedJul 10, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.

  • CVE-2024-36996MedJul 1, 2024
    risk 0.34cvss 5.3epss 0.00

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user exists on the instance by deciphering the error response that they would likely receive from the instance…

  • CVE-2024-38322MedJun 28, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869.