CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2022-29185 MEDIUM
totp-rs < 1.1.0 - Observable Timing Discrepancy in Token Comparison
CVSS 4.2
CVE-2022-24043 MEDIUM
Siemens Desigo DXR2, PXC3, PXC4, PXC5 - Username Enumeration via Login Timing Side Channel
CVSS 5.3
CVE-2022-1318 MEDIUM
Hills ComNav < 3002-19 - Inadequate Encryption Strength in Local Network Configuration Traffic
CVSS 6.2
CVE-2022-27814 LOW
swhkd 1.1.5 - Arbitrary File Existence Test via -c Option
CVSS 3.3
CVE-2022-22356 MEDIUM
IBM MQ Appliance <9.2 - Info Disclosure
CVSS 6.5
CVE-2022-24784 LOW
Statamic < 3.2.39 - Exposure of Sensitive Information via REST API Users Endpoint
CVSS 3.7
CVE-2022-0564 MEDIUM
Qlik Sense Enterprise on Windows - Info Disclosure
CVSS 5.3
CVE-2022-23643 MEDIUM
Sourcegraph 3.35.0-3.35.1 - Authenticated Exposure of Sensitive Information via Code Monitoring Feature
CVSS 6.5
CVE-2022-0569 MEDIUM
Packagist snipe/snipe-it <5.3.9 - Info Disclosure
CVSS 5.3
CVE-2022-21659 MEDIUM
Flask-AppBuilder < 3.4.4 - Unauthenticated User Enumeration via Login Timing Discrepancy
CVSS 5.3
CVE-2022-24032 MEDIUM
Azenza AxiomSL ControllerView <10.8.1 - Info Disclosure
CVSS 5.3
CVE-2022-23304 CRITICAL
hostapd and wpa_supplicant < 2.10 - Side-Channel Attack via EAP-pwd Cache Access Patterns
CVSS 9.8
CVE-2022-23303 CRITICAL
hostapd and wpa_supplicant < 2.10 - Side Channel Attack via SAE Cache Access Patterns
CVSS 9.8
CVE-2022-23106 MEDIUM
Jenkins Configuration as Code Plugin < 1.55 - Authentication Token Timing Attack
CVSS 5.3
CVE-2022-22120 MEDIUM
NocoDB 0.9-0.83.8 - User Enumeration via Password Reset Error Message
CVSS 5.3
CVE-2021-47664 MEDIUM
Franka Emika Robot <=4.0.3 - Username Enumeration
CVSS 5.3
CVE-2021-47226 HIGH
Linux Kernel - Information Disclosure via FPU State Leak on XRSTOR Failure
CVSS 7.1
CVE-2021-20556 MEDIUM
IBM Cognos Controller <11.0.0 - Info Disclosure
CVSS 5.3
CVE-2021-21575 MEDIUM
Dell BSAFE Micro Edition Suite <4.5.2 - Info Disclosure
CVSS 5.9
CVE-2021-46876 MEDIUM
eZ Publish Ibexa Kernel <7.5.15.1 - Info Disclosure
CVSS 5.3
CVE-2021-4294 LOW
OpenShift OSIN - Timing Discrepancy
CVSS 2.6
CVE-2021-4286 LOW
cocagne pysrp <1.0.16 - Info Disclosure
CVSS 2.6
CVE-2021-45925 MEDIUM
Lanner Inc IAC-AST2500A <1.10.0 - Info Disclosure
CVSS 5.3
CVE-2021-36201 MEDIUM
CCURE 9000 Firmware < 2.90 - User Account Enumeration
CVSS 4.3
CVE-2021-0975 MEDIUM
Android 13 - Unauthenticated Installed App Detection via USB Manager Side Channel
CVSS 5.5
Details
Vulnerabilities 751