Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2024-13198MEDIUMlanghsu Mblog Blog System login observable response discrepancyEPSS 0.7%CVE-2025-21510HIGHVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are EPSS 0.7%CVE-2023-25728MEDIUMThe <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interactionEPSS 0.7%CVE-2022-45416MEDIUMKeyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as PriEPSS 0.7%CVE-2022-40084MEDIUMOpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a passEPSS 0.7%CVE-2023-26215HIGHTIBCO EBX® Add-ons Path TraversalEPSS 0.7%CVE-2025-27667CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email EnumeratiEPSS 0.7%CVE-2023-27870MEDIUMIBM Spectrum Virtualize information disclosureEPSS 0.7%CVE-2023-26071HIGHAn issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In EPSS 0.7%CVE-2022-44381MEDIUMSnipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.EPSS 0.6%CVE-2022-41765MEDIUMAn issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes theEPSS 0.6%CVE-2022-35888MEDIUMAmpere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extractEPSS 0.6%CVE-2024-41952MEDIUMZitadel has an "Ignoring unknown usernames" vulnerabilityEPSS 0.6%CVE-2025-21336MEDIUMWindows Cryptographic Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-43546MEDIUMWindows Cryptographic Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-47102MEDIUMUrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.EPSS 0.6%CVE-2024-0564MEDIUMKernel: max page sharing of kernel samepage merging (ksm) may cause memory deduplicationEPSS 0.6%CVE-2023-39522MEDIUMUsername enumeration attack in goauthentikEPSS 0.6%CVE-2023-52323MEDIUMPyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.EPSS 0.6%CVE-2026-51926HIGHAn issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerEPSS 0.6%