CWE-204

Observable Response Discrepancy

Parent: CWE-203 - Observable Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

167 vulnerabilities with CWE-204
CVE-2023-49069 MEDIUM
Mendix Runtime <10.17.0, 10.12.<11, 10.6.<19 - Auth Bypass
CVSS 5.3
CVE-2023-33859 MEDIUM
IBM Security QRadar EDR <3.12 - Info Disclosure
CVSS 5.3
CVE-2023-27283 MEDIUM
IBM Aspera Orchestrator 4.0.1 - Info Disclosure
CVSS 5.3
CVE-2023-46170 MEDIUM
IBM DS8900F HMC Arbitrary File Read via File Name Enumeration
CVSS 6.5
CVE-2023-38362 MEDIUM
IBM CICS TX Advanced 10.1 - Info Disclosure
CVSS 5.3
CVE-2023-50306 MEDIUM
IBM Common Licensing 9.0 - Username Enumeration via Observable Response Discrepancy
CVSS 4.0
CVE-2023-23584 MEDIUM
Gallagher Command Centre < 8.50 - Information Disclosure via RESTAPI Response Discrepancy
CVSS 4.3
CVE-2023-37831 MEDIUM
Elenos ETG150 FM transmitter <3.12 - Info Disclosure
CVSS 5.3
CVE-2023-4095 MEDIUM
Arconte Aurea 1.5.0.0 - Info Disclosure
CVSS 5.3
CVE-2023-41885 MEDIUM
piccolo < 0.121.0 - User Enumeration via BaseUser.login
CVSS 5.3
CVE-2023-3221 MEDIUM
Password Recovery Plugin 1.2 for Roundcube - User Enumeration via Password Recovery Function
CVSS 5.3
CVE-2023-40179 MEDIUM
Silverware Games <1.3.6 - Info Disclosure
CVSS 5.3
CVE-2023-39343 MEDIUM
Sulu 2.5.0-2.5.9 - Observable Response Discrepancy via Admin Login Form
CVSS 4.3
CVE-2023-37217 MEDIUM
Tadiran Telecom Aeonix - Observable Response Discrepancy
CVSS 5.3
CVE-2023-35698 MEDIUM
SICK ICR890-4 Firmware < 2.5.0 - Observable Response Discrepancy via FTP Login
CVSS 5.3
CVE-2023-3336 MEDIUM
TN-5900 Series <3.3 - Info Disclosure
CVSS 5.3
CVE-2023-31186 MEDIUM
Avaya IX Workforce Engagement <15.2.7.1195 - Info Disclosure
CVSS 5.3
CVE-2023-28412 MEDIUM
Snapone Orvc < 7.3.0 - Information Disclosure
CVSS 5.3
CVE-2023-32346 MEDIUM
Teltonika's Remote Management System <4.10.0 - Info Disclosure
CVSS 5.3
CVE-2023-23449 MEDIUM
SICK FTMg AIR FLOW SENSOR Firmware < 2.0 - Observable Response Discrepancy via REST Interface
CVSS 5.3
CVE-2023-27464 MEDIUM
Mendix Forgot Password < 3.7.1 - Information Disclosure via Observable Response Discrepancy
CVSS 5.3
CVE-2023-1540 MEDIUM
answerdev/answer <1.0.6 - Info Disclosure
CVSS 5.3
CVE-2022-20633 MEDIUM
Cisco Enterprise Chat and Email < 12.6(1)es1 - Username Enumeration via Auth Response
CVSS 5.3
CVE-2022-39228 MEDIUM
vantage6 3.3.3-3.7.9 - User Enumeration via Login Response Timing
CVSS 5.3
CVE-2022-41697 MEDIUM
Ghost Foundation Ghost <5.9.4 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 167