Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2019-25337MEDIUMOwnCloud 8.1.8 - Username DisclosureEPSS 0.4%CVE-2024-21233MEDIUMVulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21EPSS 0.4%CVE-2025-32789LOWEspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting FunctionEPSS 0.4%CVE-2022-24695MEDIUMBluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in NonEPSS 0.4%CVE-2026-56316MEDIUMCap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/*EPSS 0.4%CVE-2021-47664MEDIUMEnumeration of valid user namesEPSS 0.4%CVE-2025-9109MEDIUMPortabilis i-Diario Password Recovery Endpoint email observable response discrepancyEPSS 0.4%CVE-2020-36888MEDIUMSpinetiX Fusion Digital Signage 3.4.8 Username Enumeration via Login ScriptEPSS 0.4%CVE-2026-19965MEDIUMautomad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancyEPSS 0.4%CVE-2024-5697MEDIUMA website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerabilEPSS 0.4%CVE-2026-65314MEDIUMElectric Postgres Sync Excluded-Column Value Inference via Subset Where ClausesEPSS 0.4%CVE-2020-10369MEDIUMCertain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory conteEPSS 0.4%CVE-2020-10367MEDIUMCertain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra"EPSS 0.4%CVE-2024-21251LOWVulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4EPSS 0.4%CVE-2024-30257LOW1Panel's password verification is suspected to have a timing attack vulnerabilityEPSS 0.4%CVE-2024-30176MEDIUMIn Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.EPSS 0.4%CVE-2023-30308MEDIUMAn issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hijack TCP sessions whicEPSS 0.4%CVE-2025-57770MEDIUMZITADEL user enumeration vulnerability in login UIEPSS 0.4%CVE-2025-6386HIGHTiming Attack Vulnerability in parisneo/lollmsEPSS 0.4%CVE-2024-54454MEDIUMAn issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable REPSS 0.4%