VYPR

CWE-204

Observable Response Discrepancy

BaseIncomplete

Description

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-331 · CAPEC-332 · CAPEC-541 · CAPEC-580

CVEs mapped to this weakness (179)

page 9 of 9
  • CVE-2026-2859MedMar 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent endpoint, which could lead to information…

  • CVE-2024-31870LowJun 15, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor to gather information about users that…

  • CVE-2023-39343MedAug 4, 2023
    risk 0.21cvss 4.3epss 0.01

    Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 security System and previous version…

  • CVE-2024-28868LowMar 20, 2024
    risk 0.17cvss 3.7epss 0.00

    Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively…

  • CVE-2022-39314LowOct 24, 2022
    risk 0.17cvss 3.7epss 0.00

    Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication Attempts. This vulnerability affects you only if you are using the `code` or `password-reset` auth…

  • CVE-2020-11063LowMay 13, 2020
    risk 0.17cvss 3.7epss 0.01

    In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigned to backend user accounts. This has…

  • CVE-2026-55998MedAug 5, 2026
    risk 0.00cvss 5.3epss 0.00

    The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the…

  • CVE-2026-14202MedAug 4, 2026
    risk 0.00cvss 5.3epss 0.00

    Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

  • CVE-2024-23574MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid…

  • CVE-2026-44753LowJul 14, 2026
    risk 0.00cvss 3.7epss 0.00

    SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate…

  • CVE-2026-61503MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including the default admin account, facilitating…

  • CVE-2026-53908MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguishable responses for valid and invalid users during username reminder and password reset operations. An attacker can leverage these differences to enumerate…

  • CVE-2026-21484MedJan 3, 2026
    risk 0.00cvss 5.3epss 0.01

    AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error messages depending on whether a username…

  • CVE-2025-67874MedDec 16, 2025
    risk 0.00cvss 6.5epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of credential compromise and may amplify…

  • CVE-2025-67500LowDec 10, 2025
    risk 0.00cvss 3.7epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have discrepancies in error handling which allow checking whether a given status exists by…

  • CVE-2025-61907MedOct 16, 2025
    risk 0.00cvss 6.5epss 0.00

    Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to…

  • CVE-2025-61789MedOct 16, 2025
    risk 0.00cvss 5.3epss 0.00

    Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to…

  • CVE-2025-31124MedMar 31, 2025
    risk 0.00cvss 5.3epss 0.00

    Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password prompt even if the user doesn't…

  • CVE-2021-39189MedSep 15, 2021
    risk 0.00cvss 5.3epss 0.01

    Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.