CWE-204— Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.— MITRE CWE catalog
198 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-204page 3 of 4
- CVE-2025-3939MEDIUMCVSS 5.3EG 5.32025-05-22
Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before…
- CVE-2024-51447MEDIUMCVSS 5.3EG 5.32025-05-13
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an observable response discrepancy vulnerability when validating u…
- CVE-2025-46736MEDIUMCVSS 5.3EG 5.32025-05-06
Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists. The issue is patc…
- CVE-2025-24342MEDIUMCVSS 5.3EG 5.32025-04-30
A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernames via multiple crafted HTTP requests.
- CVE-2025-30150MEDIUMCVSS 5.3EG 5.32025-04-08
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/accoun…
- CVE-2025-30280MEDIUMCVSS 5.3EG 5.32025-04-08
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions < V10.12.16), Mendix Runtime V10.18 (All versions < V10.18.5), Mendix Runtime V10.6 (All versions < V10.6.22), Mendix …
- CVE-2024-56476MEDIUMCVSS 5.3EG 5.32025-04-02
IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.
- CVE-2025-31124MEDIUMCVSS 5.3EG 5.32025-03-31
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the …
- CVE-2024-55198MEDIUMCVSS 5.3EG 5.32025-03-13
User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.
- CVE-2025-1101MEDIUMCVSS 5.3EG 5.32025-02-12
A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enumerate valid usernames via crafted HTTP requests.
- CVE-2025-23193MEDIUMCVSS 5.3EG 5.32025-02-11
SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does …
- CVE-2025-24980MEDIUMCVSS 5.3EG 5.32025-02-07
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has b…
- CVE-2023-37413MEDIUMCVSS 5.3EG 5.32025-01-29
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
- CVE-2024-35114MEDIUMCVSS 5.3EG 5.32025-01-25
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.
- CVE-2025-0693MEDIUMCVSS 5.3EG 5.32025-01-23
Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.
- CVE-2024-36510MEDIUMCVSS 5.3EG 5.32025-01-14
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions …
- CVE-2022-20633MEDIUMCVSS 5.3EG 5.32024-11-15
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device. This vulnerability is due to differences in aut…
- CVE-2024-52043MEDIUMCVSS 5.3EG 5.32024-11-06
Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released HumHub versions: through 1.16.2.
- CVE-2024-8651MEDIUMCVSS 5.3EG 5.32024-09-19
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.241…
- CVE-2024-34336MEDIUMCVSS 5.3EG 5.32024-09-12
User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.
- CVE-2023-49069MEDIUMCVSS 5.3EG 5.32024-09-10
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.11 only if the basic authentication mec…
- CVE-2024-42343MEDIUMCVSS 5.3EG 5.32024-09-08
Loway - CWE-204: Observable Response Discrepancy
- CVE-2024-38431MEDIUMCVSS 5.3EG 5.32024-07-30
Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy
- CVE-2024-39912MEDIUMCVSS 5.3EG 5.32024-07-15
web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. The ProfileBasedRequestOptionsBuilder method returns allowedCrede…
- CVE-2023-33859MEDIUMCVSS 5.3EG 5.32024-07-10
IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.
- CVE-2024-39211MEDIUMCVSS 5.3EG 5.32024-07-04
Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response contains a user_email field only if the user account exists.
- CVE-2024-36996MEDIUMCVSS 5.3EG 5.32024-07-01
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user exists on the instance by deciphering the error response that they …
- CVE-2024-38322MEDIUMCVSS 5.3EG 5.32024-06-28
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869.
- CVE-2024-33856MEDIUMCVSS 5.3EG 5.32024-05-07
An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Password endpoint.
- CVE-2023-27283MEDIUMCVSS 5.3EG 5.32024-05-04
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.
- CVE-2021-20556MEDIUMCVSS 5.3EG 5.32024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
- CVE-2024-1145MEDIUMCVSS 5.3EG 5.32024-03-19
User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered in the application just by looking at the request response.
- CVE-2023-38362MEDIUMCVSS 5.3EG 5.32024-03-04
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.
- CVE-2024-25146MEDIUMCVSS 5.3EG 5.32024-02-08
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exi…
- CVE-2023-37831MEDIUMCVSS 5.3EG 5.32023-10-31
An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentials are submitted.
- CVE-2023-4095MEDIUMCVSS 5.3EG 5.32023-09-19
User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to obtain a list of registered users in the application, obtaining the necessary information to perform more c…
- CVE-2023-41885MEDIUMCVSS 5.3EG 5.32023-09-12
Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUser.login` leaks enough information to a malicious user such that they would be able to successfully generate a list of …
- CVE-2023-3221MEDIUMCVSS 5.3EG 5.32023-09-04
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.
- CVE-2023-40179MEDIUMCVSS 5.3EG 5.32023-08-25
Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Recovery form would throw an error if the specified email was not found in our database. It would only display the "Enter…
- CVE-2023-37217MEDIUMCVSS 5.3EG 5.32023-07-30
Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy
- CVE-2023-35698MEDIUMCVSS 5.3EG 5.32023-07-10
Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.
- CVE-2023-3336MEDIUMCVSS 5.3EG 5.32023-07-05
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enabl…
- CVE-2023-31186MEDIUMCVSS 5.3EG 5.32023-05-30
Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
- CVE-2023-28412MEDIUMCVSS 5.3EG 5.32023-05-22
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information. …
- CVE-2023-32346MEDIUMCVSS 5.3EG 5.32023-05-22
Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already been claimed, the MA…
- CVE-2023-23449MEDIUMCVSS 5.3EG 5.32023-05-15
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses…
- CVE-2023-27464MEDIUMCVSS 5.3EG 5.32023-04-11
A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions <…
- CVE-2023-1540MEDIUMCVSS 5.3EG 5.32023-03-21
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2022-39228MEDIUMCVSS 5.3EG 5.32023-03-01
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots fr…
- CVE-2019-19030MEDIUMCVSS 5.3EG 5.32022-12-26
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
Map vulnerabilities like CWE-204 to your infrastructure
EchelonGraph correlates every CVE — across CWE-204 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →