Metalikelihood: Highseverity: HighStable

CAPEC-21Exploitation of Trusted Identifiers

Abstraction
Meta
Status
Stable
Likelihood
High
Severity
High

Description

Metadata: meta CAPEC pattern, status stable, likelihood high, severity high. Underlying weaknesses: CWE-290, CWE-302, CWE-346, CWE-539, CWE-6 (and 4 more). Mapped ATT&CK techniques: [object Object], [object Object], [object Object]. Metadata: meta CAPEC pattern, status stable, likelihood high, severity high. Underlying weaknesses: CWE-290, CWE-302, CWE-346, CWE-539, CWE-6 (and 4 more). Mapped ATT&CK techniques: [object Object], [object Object], [object Object].

Related weaknesses· 9

CWE-290CWE-302CWE-346CWE-539CWE-6CWE-384CWE-664CWE-602CWE-642

MITRE ATT&CK crosswalk· 3

T1134: Access Token ManipulationT1528: Steal Application Access TokenT1539: Steal Web Session Cookie

Exploits9

TypeTargetConfidenceTier
WeaknessExternal Control of Critical State Datacwe-642100%live
WeaknessAuthentication Bypass by Spoofingcwe-290100%live
WeaknessUse of Persistent Cookies Containing Sensitive Informationcwe-539100%live
WeaknessImproper Control of a Resource Through its Lifetimecwe-664100%live
WeaknessAuthentication Bypass by Assumed-Immutable Datacwe-302100%live
WeaknessJ2EE Misconfiguration: Insufficient Session-ID Lengthcwe-6100%live
WeaknessOrigin Validation Errorcwe-346100%live
WeaknessClient-Side Enforcement of Server-Side Securitycwe-602100%live
WeaknessSession Fixationcwe-384100%live

Related to3

TypeTargetConfidenceTier
TechniqueSteal Web Session Cookiet1539100%live
TechniqueSteal Application Access Tokent1528100%live
TechniqueAccess Token Manipulationt1134100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Exploitation of Improperly Controlled Hardware Security Identifiers
CAPEC
Exploit Non-Production Interfaces
CAPEC
Use of Known Domain Credentials
CAPEC
Privilege Escalation
CAPEC
Privilege Abuse
CAPEC
Exploitation of Improperly Configured or Implemented Memory Protections
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.