The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
167 vulnerabilities with CWE-204
CVE-2022-39315
MEDIUM
Kirby < 3.5.8.2, 3.6.6.2, 3.7.5.1, 3.8.1 - User Enumeration via Error Message Timing
CVSS 6.5
CVE-2022-22520
MEDIUM
MymbCONNECT24 <v2.11.2 - Info Disclosure
CVSS 5.3
CVE-2022-1989
MEDIUM
CODESYS Visualization <V4.2.0.0 - Info Disclosure
CVSS 5.3
CVE-2022-31248
MEDIUM
SUSE Manager Server <4.1.46-1, <4.2.37-1 - Info Disclosure
CVSS 5.3
CVE-2022-0564
MEDIUM
Qlik Sense Enterprise on Windows - Info Disclosure
CVSS 5.3
CVE-2021-47717
MEDIUM
IntelliChoice eFORCE Software Suite 2.5.9 - Info Disclosure
CVE-2021-20556
MEDIUM
IBM Cognos Controller <11.0.0 - Info Disclosure
CVSS 5.3
CVE-2021-36201
MEDIUM
CCURE 9000 Firmware < 2.90 - User Account Enumeration
CVSS 4.3
CVE-2021-20049
HIGH
SonicWall SMA100/SMA200/SMA210/SMA400/SMA410/SMA500v < 10.0.0.0 - Unauthenticated Username Enumeration
CVSS 7.5
CVE-2021-34580
HIGH
mbconnect24 and mymbconnect24 <= 2.9.0 - Unauthenticated User Enumeration via Login Response Discrepancy
CVSS 7.5
CVE-2021-38476
MEDIUM
InHand Networks IR615 Router <2.3.0.r4870 - Info Disclosure
CVSS 6.5
CVE-2021-39189
MEDIUM
pimcore < 10.1.3 - Username Enumeration via Forgot Password Functionality
CVSS 5.3
CVE-2020-11063
LOW
TYPO3 CMS <10.4.1 - Info Disclosure
CVSS 3.7
CVE-2019-25338
MEDIUM
DokuWiki 2018-04-22b - Info Disclosure
CVSS 5.3
CVE-2019-19030
MEDIUM
Cloud Native Computing Foundation Harbor <1.10.3, <2.0.1 - Info Dis...
CVSS 5.3
CVE-2018-25350
CRITICAL
userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
CVSS 9.8
CVE-2016-9499
MEDIUM
Accellion FTP Server < FTA_9_12_220 - Username Enumeration via Invalid Login Response
CVSS 5.3
Details
Vulnerabilities
167