Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2021-10-07 CVE-2021-20376 Information Exposure Through Discrepancy vulnerability in IBM Sterling B2B Integrator
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages.
network
low complexity
ibm CWE-203
4.0
2021-09-22 CVE-2021-38153 Information Exposure Through Discrepancy vulnerability in multiple products
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful.
network
high complexity
apache quarkus oracle CWE-203
5.9
2021-09-16 CVE-2021-34576 Information Exposure Through Discrepancy vulnerability in Kadenvodomery Picoflux AIR Firmware
In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists.
low complexity
kadenvodomery CWE-203
3.3
2021-09-15 CVE-2021-39189 Information Exposure Through Discrepancy vulnerability in Pimcore
Pimcore is an open source data & experience management platform.
network
low complexity
pimcore CWE-203
5.0
2021-09-01 CVE-2021-37151 Information Exposure Through Discrepancy vulnerability in Cyberark Identity
CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid.
network
low complexity
cyberark CWE-203
5.3
2021-08-10 CVE-2020-25082 Information Exposure Through Discrepancy vulnerability in Nuvoton Npct75X Firmware
An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel attack against ECDSA, because of an Observable Timing Discrepancy.
1.9
2021-08-08 CVE-2021-38209 Information Exposure Through Discrepancy vulnerability in Linux Kernel
net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces.
local
low complexity
linux CWE-203
2.1
2021-08-05 CVE-2021-3642 Information Exposure Through Discrepancy vulnerability in multiple products
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled.
3.5
2021-08-02 CVE-2021-37848 Information Exposure Through Discrepancy vulnerability in Pengutronix Barebox
common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash comparison.
network
low complexity
pengutronix CWE-203
5.0
2021-08-02 CVE-2021-34575 Information Exposure Through Discrepancy vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by checking what kind of response the server sends.
network
low complexity
mbconnectline CWE-203
5.0