CWE-204

Observable Response Discrepancy

Parent: CWE-203 - Observable Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

167 vulnerabilities with CWE-204
CVE-2025-5485 HIGH
Web Management Interface - Info Disclosure
CVSS 8.6
CVE-2025-49187 MEDIUM
Sick Field Analytics - Username Enumeration via Different Error Messages
CVSS 5.3
CVE-2025-0163 MEDIUM
IBM Security Verify Access Appliance & Docker <10.0.9 - Info Disclo...
CVSS 5.3
CVE-2025-3939 MEDIUM
Tridium Niagara Framework and Enterprise Security < 4.14.2, < 4.15.1, < 4.10.11 - Observable Response Discrepancy
CVSS 5.3
CVE-2025-48015 LOW
SEL-5056 Software-Defined Network Flow Controller < 2.16.0 - Username Enumeration via Login Response Discrepancy
CVSS 3.7
CVE-2025-46736 MEDIUM
Umbraco <10.8.10, <13.8.1 - Info Disclosure
CVSS 5.3
CVE-2025-24342 MEDIUM
Bosch Rexroth ctrlX OS 1.12.0-1.12.8, 1.20.0-1.20.6, 2.6.0-2.6.7 - Unauthenticated Username Enumeration
CVSS 5.3
CVE-2025-30150 MEDIUM
Shopware < 6.5.8.18 and 6.6.0.0-6.6.10.3 - Account Enumeration via Password Recovery Endpoint
CVSS 5.3
CVE-2025-30280 MEDIUM
Mendix Runtime <10.21.0, 10.12.16, 10.18.5, 10.6.22, 8.18.35, 9.24....
CVSS 5.3
CVE-2025-31124 MEDIUM
zitadel < 2.63.9 - Username Enumeration via Normalization Bypass
CVSS 5.3
CVE-2025-2910 MEDIUM
Fermax MeetMe < 2024-09 - User Enumeration via Password Reset Error Messages
CVE-2025-24023 LOW
Flask-AppBuilder < 4.5.3 - Unauthenticated Username Enumeration via Timing Attack
CVSS 3.7
CVE-2025-1101 MEDIUM
Q-Free MaxTime <= 2.11.0 - Info Disclosure
CVSS 5.3
CVE-2025-23193 MEDIUM
SAP NetWeaver Server ABAP - Info Disclosure
CVSS 5.3
CVE-2025-24980 MEDIUM
pimcore/admin-ui-classic-bundle < 1.7.4 - User Enumeration via Forgot Password Error Message
CVSS 5.3
CVE-2025-0693 MEDIUM
AWS Sign-in < unknown - Info Disclosure
CVSS 5.3
CVE-2025-23214 MEDIUM
Cosmos-Server < 0.17.7 - User Enumeration via Login Error Code
CVE-2024-23574 MEDIUM
Hclsoftware Aftermarket Epc - Observable Response Discrepancy
CVSS 5.3
CVE-2024-0391 MEDIUM
Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Discovery
CVSS 5.3
CVE-2024-51447 MEDIUM
Polarion ALM V2310 and V2404 < V2404.2 - Unauthenticated Observable Response Discrepancy in Username Validation
CVSS 5.3
CVE-2024-56476 MEDIUM
IBM TXSeries for Multiplatforms <9.1, 11.1 - Info Disclosure
CVSS 5.3
CVE-2024-55198 MEDIUM
Celk Sistemas Celk Saude <3.1.252.1 - Info Disclosure
CVSS 5.3
CVE-2024-35114 MEDIUM
IBM Control Center 6.2.1 and 6.3.1 - Username Enumeration via Observable Login Discrepancy
CVSS 5.3
CVE-2024-36510 MEDIUM
FortiClientEMS/FortiSOAR <7.5.0 - Info Disclosure
CVSS 5.3
CVE-2024-42174 LOW
HCL MyXalytics - Username Enumeration via Observable Response Discrepancy
CVSS 3.7
Details
Vulnerabilities 167