Weaknesses of type CWE-204

191 results

Vazamento de informações através de respostas diferenciadas

A aplicação retorna respostas diferentes (tempo de processamento, mensagens de erro, código HTTP, tamanho da resposta) dependendo do estado interno do sistema, permitindo que atacantes deduzam informações sensíveis sem autorização. Por exemplo, responder com 'usuário não encontrado' versus 'senha incorreta' vaza a existência de contas.

Example

Um formulário de login que retorna 'usuário inexistente' para um email não cadastrado, mas 'credenciais inválidas' quando o email existe, permite que invasores enumerem contas válidas da plataforma sem precisar quebrar senhas.

How to mitigate

Padronize todas as respostas de erro (mensagens e tempo de processamento) para cenários de falha similares. Use mensagens genéricas como 'credenciais inválidas' independente do motivo real, e implemente rate limiting para dificultar enumeração automatizada.

CVE-2023-47159MEDIUMIBM Sterling File Gateway information disclosureEPSS 0.3%CVE-2026-81033MEDIUMAutomatisch through 0.15.0 User Enumeration via Forgot-Password Response DiscrepancyEPSS 0.3%CVE-2025-9824MEDIUMUser Enumeration via Response TimingEPSS 0.3%CVE-2025-69243MEDIUMUser enumeration in Raytha CMSEPSS 0.3%CVE-2026-33688MEDIUMAVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery EndpointEPSS 0.3%CVE-2026-20195MEDIUMCisco Identity Services Engine Observable Response Discrepancy VulnerabilityEPSS 0.3%CVE-2025-54129MEDIUMHAXiam allows for User EnumerationEPSS 0.3%CVE-2026-34264MEDIUMInformation Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANAEPSS 0.3%CVE-2026-24664MEDIUMOpen eClass is Vulnerable to Username Enumeration via Login Response DiscrepanciesEPSS 0.3%CVE-2025-67806LOWThe login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing acEPSS 0.3%CVE-2026-53422LOWSFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured rootEPSS 0.3%CVE-2025-56764MEDIUMTrivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messEPSS 0.3%CVE-2024-42174LOWHCL MyXalytics is affected by username enumeration vulnerabilityEPSS 0.3%CVE-2026-89173MEDIUMKingdom Communication Associated|Smart Video Intercom System - Sensitive Data ExposureEPSS 0.3%CVE-2026-15747CRITICALMojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracleEPSS 0.3%CVE-2025-48015LOWObservable Response DiscrepancyEPSS 0.3%CVE-2026-14672MEDIUMPostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracleEPSS 0.3%CVE-2026-72588MEDIUMbluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password RecoveryEPSS 0.3%CVE-2026-42218MEDIUMXRDP is vulnerable to a server timing attack, leading to user enumerationEPSS 0.3%CVE-2026-19205HIGHUser Enumeration in GastroMenum's GastroMenum Web PanelEPSS 0.2%