The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with
Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to en
Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow
Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an
Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application retu
A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerabl
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enume
HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versio
A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumer
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown func
HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration o
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users
Failed login response could be different depending on whether the username was local or central.
A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown fun
Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 thro
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as
User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows a
Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authen
IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumera
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbi
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version
Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page ha
Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 befor
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTT
User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepanc
An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the r
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exp
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an a
Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response
IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM
web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that
Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy
Loway - CWE-204: Observable Response Discrepancy
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mech
User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists i
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whet
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker
The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of message
The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM
A vulnerability has been found in Surya2Developer Hostel Management Service 1.0 and classified as problematic. Affected
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vu
A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this
A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown
A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue aff
IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local a
Frequently Asked Questions
What is CWE-204?
CWE-204 (CWE-204) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-204?
There are 181 CVE records associated with CWE-204 in our database. Of these, 2 are critical severity, 11 are high severity, and 140 are medium severity.
How can I protect against CWE-204 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-204 using AI-powered security agents.
Detect CWE-204 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-204 vulnerabilities across your infrastructure.
Get Started