The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
167 vulnerabilities with CWE-204
CVE-2025-5485
HIGH
Web Management Interface - Info Disclosure
CVSS 8.6
CVE-2025-49187
MEDIUM
Sick Field Analytics - Username Enumeration via Different Error Messages
CVSS 5.3
CVE-2025-0163
MEDIUM
IBM Security Verify Access Appliance & Docker <10.0.9 - Info Disclo...
CVSS 5.3
CVE-2025-3939
MEDIUM
Tridium Niagara Framework and Enterprise Security < 4.14.2, < 4.15.1, < 4.10.11 - Observable Response Discrepancy
CVSS 5.3
CVE-2025-48015
LOW
SEL-5056 Software-Defined Network Flow Controller < 2.16.0 - Username Enumeration via Login Response Discrepancy
CVSS 3.7
CVE-2025-46736
MEDIUM
Umbraco <10.8.10, <13.8.1 - Info Disclosure
CVSS 5.3
CVE-2025-24342
MEDIUM
Bosch Rexroth ctrlX OS 1.12.0-1.12.8, 1.20.0-1.20.6, 2.6.0-2.6.7 - Unauthenticated Username Enumeration
CVSS 5.3
CVE-2025-30150
MEDIUM
Shopware < 6.5.8.18 and 6.6.0.0-6.6.10.3 - Account Enumeration via Password Recovery Endpoint
CVSS 5.3
CVE-2025-30280
MEDIUM
Mendix Runtime <10.21.0, 10.12.16, 10.18.5, 10.6.22, 8.18.35, 9.24....
CVSS 5.3
CVE-2025-31124
MEDIUM
zitadel < 2.63.9 - Username Enumeration via Normalization Bypass
CVSS 5.3
CVE-2025-2910
MEDIUM
Fermax MeetMe < 2024-09 - User Enumeration via Password Reset Error Messages
CVE-2025-24023
LOW
Flask-AppBuilder < 4.5.3 - Unauthenticated Username Enumeration via Timing Attack
CVSS 3.7
CVE-2025-1101
MEDIUM
Q-Free MaxTime <= 2.11.0 - Info Disclosure
CVSS 5.3
CVE-2025-23193
MEDIUM
SAP NetWeaver Server ABAP - Info Disclosure
CVSS 5.3
CVE-2025-24980
MEDIUM
pimcore/admin-ui-classic-bundle < 1.7.4 - User Enumeration via Forgot Password Error Message
CVSS 5.3
CVE-2025-0693
MEDIUM
AWS Sign-in < unknown - Info Disclosure
CVSS 5.3
CVE-2025-23214
MEDIUM
Cosmos-Server < 0.17.7 - User Enumeration via Login Error Code
CVE-2024-23574
MEDIUM
Hclsoftware Aftermarket Epc - Observable Response Discrepancy
CVSS 5.3
CVE-2024-0391
MEDIUM
Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Discovery
CVSS 5.3
CVE-2024-51447
MEDIUM
Polarion ALM V2310 and V2404 < V2404.2 - Unauthenticated Observable Response Discrepancy in Username Validation
CVSS 5.3
CVE-2024-56476
MEDIUM
IBM TXSeries for Multiplatforms <9.1, 11.1 - Info Disclosure
CVSS 5.3
CVE-2024-55198
MEDIUM
Celk Sistemas Celk Saude <3.1.252.1 - Info Disclosure
CVSS 5.3
CVE-2024-35114
MEDIUM
IBM Control Center 6.2.1 and 6.3.1 - Username Enumeration via Observable Login Discrepancy
CVSS 5.3
CVE-2024-36510
MEDIUM
FortiClientEMS/FortiSOAR <7.5.0 - Info Disclosure
CVSS 5.3
CVE-2024-42174
LOW
HCL MyXalytics - Username Enumeration via Observable Response Discrepancy
CVSS 3.7
Details
Vulnerabilities
167