← Back
CWE-203

751 CVEs • Abstraction: Base

Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

JSON object

Loading...

CVEs (751)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Ipados
Iphone Os
Jun 17, 2026
May 14, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine a user's current location.
1Ibm
1Aspera Orchestrator
Jun 17, 2026
May 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.
1Ibm
1Cognos Controller
Jun 17, 2026
May 3, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
1Logpoint
1Siem
Jun 17, 2026
May 1, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.
-
-
Jun 17, 2026
Apr 25, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attack...Show more
A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.Show less
1Fit2cloud
11panel
Jun 17, 2026
Apr 18, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol instead hmac.Equal. This may lead to a timing attack vulnerability. This v...Show more
1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol instead hmac.Equal. This may lead to a timing attack vulnerability. This vulnerability is fixed in 1.10.3-lts.Show less
1Microsoft
4Windows Server 2016
Windows Server 2019Windows Server 2022+1 more
Jun 17, 2026
Apr 9, 2024
N/A· v4
6.6 MEDIUM· v3
N/A· v2
Windows DNS Server Remote Code Execution Vulnerability
-
-
Jun 17, 2026
Apr 4, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A timing-based side-channel flaw exists in the rust-openssl package, which could be sufficient to recover a plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would...Show more
A timing-based side-channel flaw exists in the rust-openssl package, which could be sufficient to recover a plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages for decryption. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.Show less
1Cdex
1Cdex
Jun 17, 2026
Mar 21, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.This issue affects CDeX applicat...Show more
This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.This issue affects CDeX application versions through 5.7.1. Show less
1Umbraco
1Umbraco Cms
Jun 17, 2026
Mar 20, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaro...Show more
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively using external logins.Show less
2Debian
Mozilla
3Debian Linux
FirefoxThunderbird
Jun 17, 2026
Mar 19, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115...Show more
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.Show less
1Delinea
1Secret Server
Jun 17, 2026
Mar 14, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token...Show more
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint.Show less
-
-
Jun 17, 2026
Mar 12, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
A potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow memory tampering. HP is releasing mitigation for the potential vulnerability.
1Icewhale
1Casaos Userservice
Jun 17, 2026
Mar 6, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An...Show more
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS username using the application response. If the username is incorrect application gives the error `**User does not exist**`. If the password is incorrect application gives the error `**Invalid password**`. Version 0.4.7 fixes this issue.Show less
1Ibm
1Cics Tx
Jun 17, 2026
Mar 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.
1Mintplexlabs
1Anythingllm
Jun 17, 2026
Feb 26, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison. The r...Show more
Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison. The risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to executeShow less
1Liveboxcloud
1Vdesk
Jun 17, 2026
Feb 21, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SUR...Show more
An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.Show less
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Feb 20, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions a...Show more
User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the request's response time.Show less
1Ibm
1Common Licensing
Jun 17, 2026
Feb 20, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.
1Hp
27Elite Mini 600 G9 Firmware
Elite Mini 800 G9 FirmwareElite Sff 600 G9 Firmware+24 more
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance...Show more
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.Show less