VYPR

CWE-204

Observable Response Discrepancy

BaseIncomplete

Description

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-331 · CAPEC-332 · CAPEC-541 · CAPEC-580

CVEs mapped to this weakness (179)

page 5 of 9
  • CVE-2024-33856MedMay 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Password endpoint.

  • CVE-2023-27283MedMay 4, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

  • CVE-2021-20556MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.

  • CVE-2024-1145MedMar 19, 2024
    risk 0.34cvss 5.3epss 0.00

    User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered in the application just by looking at the request response.

  • CVE-2023-38362MedMar 4, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.

  • CVE-2024-25146MedFeb 8, 2024
    risk 0.34cvss 5.3epss 0.01

    Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have…

  • CVE-2023-37831MedOct 31, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentials are submitted.

  • CVE-2023-4095MedSep 19, 2023
    risk 0.34cvss 5.3epss 0.00

    User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to obtain a list of registered users in the application, obtaining the necessary information to perform more complex attacks on the platform.

  • CVE-2023-3221MedSep 4, 2023
    risk 0.34cvss 5.3epss 0.00

    User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.

  • CVE-2023-40179MedAug 25, 2023
    risk 0.34cvss 5.3epss 0.00

    Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Recovery form would throw an error if the specified email was not found in our database. It would only display the "Enter the code" form if the email is…

  • CVE-2023-37217MedJul 30, 2023
    risk 0.34cvss 5.3epss 0.00

    Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy

  • CVE-2023-35698MedJul 10, 2023
    risk 0.34cvss 5.3epss 0.01

    Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.

  • CVE-2023-3336MedJul 5, 2023
    risk 0.34cvss 5.3epss 0.01

    TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users.…

  • CVE-2023-31186MedMay 30, 2023
    risk 0.34cvss 5.3epss 0.00

    Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy

  • CVE-2023-28412MedMay 22, 2023
    risk 0.34cvss 5.3epss 0.00

    When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.

  • CVE-2023-32346MedMay 22, 2023
    risk 0.34cvss 5.3epss 0.01

    Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already been claimed, the MAC address of a device has already been…

  • CVE-2023-27464MedApr 11, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.1.1). The affected versions of the…

  • CVE-2026-34319MedApr 21, 2026
    risk 0.33cvss 5.0epss 0.00

    Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2024-28232MedApr 1, 2024
    risk 0.33cvss 6.2epss 0.01

    Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in…

  • CVE-2024-24766MedMar 6, 2024
    risk 0.33cvss 6.2epss 0.01

    CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS username using the…