VYPR

CWE-204

Observable Response Discrepancy

BaseIncomplete

Description

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-331 · CAPEC-332 · CAPEC-541 · CAPEC-580

CVEs mapped to this weakness (179)

page 8 of 9
  • CVE-2025-30150MedApr 8, 2025
    risk 0.27cvss 5.3epss 0.00

    Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-password you get the…

  • CVE-2025-24980MedFeb 7, 2025
    risk 0.27cvss 5.3epss 0.01

    pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been…

  • CVE-2024-39912MedJul 15, 2024
    risk 0.27cvss 5.3epss 0.00

    web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. The ProfileBasedRequestOptionsBuilder method returns allowedCredentials without any credentials if no…

  • CVE-2023-41885MedSep 12, 2023
    risk 0.27cvss 5.3epss 0.00

    Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUser.login` leaks enough information to a malicious user such that they would be able to successfully generate a list of valid users on the platform. As Piccolo…

  • CVE-2022-39228MedMar 1, 2023
    risk 0.27cvss 5.3epss 0.01

    vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots from obtaining usernames. However, if a…

  • CVE-2023-50306MedFeb 20, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.

  • CVE-2026-8242LowMay 10, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy. The attack is possible to be carried out…

  • CVE-2025-67806LowApr 1, 2026
    risk 0.24cvss 3.7epss 0.00

    The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer versions.

  • CVE-2026-4045LowMar 12, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable response discrepancy. The attack can be executed remotely. A high complexity level…

  • CVE-2025-9109LowAug 18, 2025
    risk 0.24cvss 3.7epss 0.00

    A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible…

  • CVE-2025-48015LowMay 20, 2025
    risk 0.24cvss 3.7epss 0.00

    Failed login response could be different depending on whether the username was local or central.

  • CVE-2025-24023LowMar 3, 2025
    risk 0.24cvss 3.7epss 0.00

    Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.

  • CVE-2024-42174LowJan 11, 2025
    risk 0.24cvss 3.7epss 0.00

    HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of valid usernames.

  • CVE-2024-13198LowJan 9, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The complexity of an attack…

  • CVE-2024-13028LowDec 29, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file /login. The manipulation of the argument username leads to observable response discrepancy. The attack may be…

  • CVE-2024-12663LowDec 16, 2024
    risk 0.24cvss 3.7epss 0.00

    A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads to observable response discrepancy. The attack can be…

  • CVE-2024-6056LowJun 17, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-password of the component Password Reset Handler. The manipulation of the argument Email leads to…

  • CVE-2024-2482LowMar 15, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability has been found in Surya2Developer Hostel Management Service 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /check_availability.php of the component HTTP POST Request Handler. The manipulation of the…

  • CVE-2026-53422MedJul 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. The SSH_FXP_REALPATH handler in ssh_sftpd calls relate_file_name/3…

  • CVE-2026-39851MedApr 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and…