CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 11 of 17
- CVE-2023-3336MEDIUMCVSS 5.3EG 5.32023-07-05
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enabl…
- CVE-2023-37305MEDIUMCVSS 5.3EG 5.32023-06-30
An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.
- CVE-2023-34344MEDIUMCVSS 5.3EG 5.32023-06-12
AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username, which may lead to information disclosure.
- CVE-2023-33518MEDIUMCVSS 5.3EG 5.32023-06-05
emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request.
- CVE-2023-31186MEDIUMCVSS 5.3EG 5.32023-05-30
Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
- CVE-2023-28015MEDIUMCVSS 5.3EG 5.32023-05-23
The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not. The attacker c…
- CVE-2023-28412MEDIUMCVSS 5.3EG 5.32023-05-22
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information. …
- CVE-2023-23449MEDIUMCVSS 5.3EG 5.32023-05-15
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses…
- CVE-2022-40482MEDIUMCVSS 5.3EG 5.32023-04-25
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials …
- CVE-2023-30458MEDIUMCVSS 5.3EG 5.32023-04-24
A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username…
- CVE-2023-27464MEDIUMCVSS 5.3EG 5.32023-04-11
A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions <…
- CVE-2023-1540MEDIUMCVSS 5.3EG 5.32023-03-21
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2023-1538MEDIUMCVSS 5.3EG 5.32023-03-21
Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2021-46876MEDIUMCVSS 5.3EG 5.32023-03-12
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.
- CVE-2023-25806MEDIUMCVSS 5.3EG 5.32023-03-02
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it…
- CVE-2022-39228MEDIUMCVSS 5.3EG 5.32023-03-01
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots fr…
- CVE-2023-0440MEDIUMCVSS 5.3EG 5.32023-01-23
Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6.
- CVE-2022-42288MEDIUMCVSS 5.3EG 5.32023-01-13
NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.
- CVE-2022-30332MEDIUMCVSS 5.3EG 5.32023-01-10
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows re…
- CVE-2022-41765MEDIUMCVSS 5.3EG 5.32022-12-26
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.
- CVE-2022-44381MEDIUMCVSS 5.3EG 5.32022-12-25
Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
- CVE-2022-46392MEDIUMCVSS 5.3EG 5.32022-12-15
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA p…
- CVE-2022-45163MEDIUMCVSS 5.3EG 5.32022-11-18
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i…
- CVE-2022-20940MEDIUMCVSS 5.3EG 5.32022-11-15
A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of counter…
- CVE-2021-45925MEDIUMCVSS 5.3EG 5.32022-10-24
Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
- CVE-2022-40084MEDIUMCVSS 5.3EG 5.32022-10-20
OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.
- CVE-2022-43412MEDIUMCVSS 5.3EG 5.32022-10-19
Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to ob…
- CVE-2022-43411MEDIUMCVSS 5.3EG 5.32022-10-19
Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webh…
- CVE-2022-36105MEDIUMCVSS 5.3EG 5.32022-09-13
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that observing response time during user authentication (backend and frontend) can be used to distinguish between existing a…
- CVE-2022-37146MEDIUMCVSS 5.3EG 5.32022-09-08
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users conf…
- CVE-2022-1989MEDIUMCVSS 5.3EG 5.32022-08-23
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.
- CVE-2022-36885MEDIUMCVSS 5.3EG 5.32022-07-27
Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook sig…
- CVE-2022-32425MEDIUMCVSS 5.3EG 5.32022-07-14
The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.
- CVE-2022-20752MEDIUMCVSS 5.3EG 5.32022-07-06
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a…
- CVE-2021-41634MEDIUMCVSS 5.3EG 5.32022-06-24
A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
- CVE-2022-24043MEDIUMCVSS 5.3EG 5.32022-05-20
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The logi…
- CVE-2021-33845MEDIUMCVSS 5.3EG 5.32022-05-06
The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.
- CVE-2022-0564MEDIUMCVSS 5.3EG 5.32022-02-21
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful explo…
- CVE-2022-0569MEDIUMCVSS 5.3EG 5.32022-02-14
Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
- CVE-2021-45901MEDIUMCVSS 5.3EG 5.32022-02-10
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
- CVE-2021-39021MEDIUMCVSS 5.3EG 5.32022-02-02
IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration. IBM X-Force ID: 21…
- CVE-2022-21659MEDIUMCVSS 5.3EG 5.32022-01-31
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate exis…
- CVE-2022-24032MEDIUMCVSS 5.3EG 5.32022-01-30
Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames on the platform because a failed login attempt produces a different error message when the username is valid.
- CVE-2019-25056MEDIUMCVSS 5.3EG 5.32022-01-26
In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mechanism.
- CVE-2022-23106MEDIUMCVSS 5.3EG 5.32022-01-12
Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.
- CVE-2022-22120MEDIUMCVSS 5.3EG 5.32022-01-10
In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered…
- CVE-2021-20147MEDIUMCVSS 5.3EG 5.32022-01-03
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
- CVE-2020-35398MEDIUMCVSS 5.3EG 5.32021-12-23
An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.
- CVE-2021-44876MEDIUMCVSS 5.3EG 5.32021-12-21
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application coun…
- CVE-2021-44875MEDIUMCVSS 5.3EG 5.32021-12-21
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application coun…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →