VYPR

CWE-204

Observable Response Discrepancy

BaseIncomplete

Description

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-331 · CAPEC-332 · CAPEC-541 · CAPEC-580

CVEs mapped to this weakness (179)

page 6 of 9
  • CVE-2025-67807MedApr 1, 2026
    risk 0.31cvss 4.7epss 0.00

    The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behaviour in newer versions.

  • CVE-2025-9824MedSep 3, 2025
    risk 0.31cvss 5.9epss 0.00

    ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a…

  • CVE-2024-40627MedJul 15, 2024
    risk 0.31cvss 5.8epss 0.01

    Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by `OpaMiddleware`, even when they lack authentication, and are passed through directly to the application. `OpaMiddleware` allows all HTTP `OPTIONS` requests…

  • CVE-2026-47083MedJul 16, 2026
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages…

  • CVE-2026-24097MedMar 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to…

  • CVE-2026-24332MedJan 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are…

  • CVE-2025-42903MedOct 14, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or…

  • CVE-2025-54129MedJul 21, 2025
    risk 0.28cvss 4.3epss 0.00

    HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versions 11.0.4 and below, the application returns a 200 response when requesting the data of a valid user and a 404 response when requesting the data of an invalid…

  • CVE-2023-47159MedJan 27, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.

  • CVE-2024-45231MedOct 8, 2024
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and…

  • CVE-2024-47129MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.00

    The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.

  • CVE-2024-41715MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.00

    The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.

  • CVE-2024-47059MedSep 18, 2024
    risk 0.28cvss 4.3epss 0.00

    When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’…

  • CVE-2023-23584MedDec 18, 2023
    risk 0.28cvss 4.3epss 0.01

    An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior…

  • CVE-2023-1540MedMar 21, 2023
    risk 0.28cvss 5.3epss 0.01

    Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

  • CVE-2019-19030MedDec 26, 2022
    risk 0.28cvss 5.3epss 0.02

    Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

  • CVE-2021-36201MedOct 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.

  • CVE-2022-21659MedJan 31, 2022
    risk 0.28cvss 5.3epss 0.01

    Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accounts by timing the response…

  • CVE-2026-73306MedAug 12, 2026
    risk 0.27cvss 5.3epss 0.00

    Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/middleware/emailLockout.ts returned…

  • CVE-2026-72588MedAug 10, 2026
    risk 0.27cvss 5.3epss 0.00

    A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a…