← Back
CWE-204

168 CVEs • Abstraction: Base

Observable Response Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

JSON object

Loading...

CVEs (168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 24, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.
-
-
Jun 17, 2026
Jun 12, 2025
8.8 HIGH· v4
8.6 HIGH· v3
N/A· v2
User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or...Show more
User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or decrementing from known identifiers or through enumerating random digit sequences.Show less
1Sick
1Field Analytics
Jun 17, 2026
Jun 12, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until...Show more
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.Show less
1Ibm
2Security Verify Access
Security Verify Access Docker
Jun 17, 2026
Jun 11, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
1Tridium
2Niagara
Niagara Enterprise Security
Jun 17, 2026
May 22, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: be...Show more
Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.Show less
-
-
Jun 17, 2026
May 20, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
Failed login response could be different depending on whether the username was local or central.
1Siemens
1Polarion Alm
Jun 17, 2026
May 13, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an observable response discrepancy vulnerabilit...Show more
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an observable response discrepancy vulnerability when validating usernames. This could allow an unauthenticated remote attacker to distinguish between valid and invalid usernames.Show less
1Umbraco
1Umbraco Cms
Jun 17, 2026
May 6, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists...Show more
Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists. The issue is patched in versions 10.8.10 and 13.8.1. No known workarounds are available.Show less
-
-
Jun 17, 2026
Apr 30, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernames via multiple crafted HTTP requests.
1Shopware
1Shopware
Jun 17, 2026
Apr 8, 2025
5.5 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoin...Show more
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-password you get the response, which indicates clearly that there is no account for this customer. In contrast you get a success response if the account was found. This vulnerability is fixed in Shopware 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.Show less
-
-
Jun 17, 2026
Apr 8, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions < V10.12.16), Mendix Runtime V10.18 (All versions < V10.18.5), Mendix Runtime V10.6 (All versions <...Show more
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions < V10.12.16), Mendix Runtime V10.18 (All versions < V10.18.5), Mendix Runtime V10.6 (All versions < V10.6.22), Mendix Runtime V8 (All versions < V8.18.35), Mendix Runtime V9 (All versions < V9.24.34). Affected applications allow for entity enumeration due to distinguishable responses in certain client actions. This could allow an unauthenticated remote attacker to list all valid entities and attribute names of a Mendix Runtime-based application.Show less
1Ibm
1Txseries For Multiplatforms
Jun 17, 2026
Apr 2, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.
1Zitadel
1Zitadel
Jun 17, 2026
Mar 31, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZIT...Show more
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password prompt even if the user doesn't exist and report "Username or Password invalid". While the setting was correctly respected during the login flow, the user's username was normalized leading to a disclosure of the user's existence. This vulnerability is fixed in 2.71.6, 2.70.8, 2.69.9, 2.68.9, 2.67.13, 2.66.16, 2.65.7, 2.64.6, and 2.63.9.Show less
-
-
Jun 17, 2026
Mar 28, 2025
6.9 MEDIUM· v4
N/A· v3
N/A· v2
User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages.
1Celk
1Celk Saude
Jun 17, 2026
Mar 13, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.
1Dpgaspar
1Flask Appbuilder
Jun 17, 2026
Mar 3, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing reque...Show more
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.Show less
1Q Free
1Maxtime
Jun 17, 2026
Feb 12, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enumerate valid usernames via crafted HTTP requests.
1Sap
1Sap Basis
Jun 17, 2026
Feb 11, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive informatio...Show more
SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability.Show less
1Pimcore
1Admin Classic Bundle
Jun 17, 2026
Feb 7, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic...Show more
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Ibm
1Aspera Faspex
Jun 17, 2026
Jan 29, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.