Detailedseverity: MediumDraft
CAPEC-226Session Credential Falsification through Manipulation
Abstraction
Detailed
Status
Draft
Severity
Medium
Description
An attacker manipulates an existing credential in order to gain access to a target application. Session credentials allow users to identify themselves to a service after an initial authentication without needing to resend the authentication information (usually a username and password) with every message. An attacker may be able to manipulate a credential sniffed from an existing connection in order to gain access to a target server.
Related weaknesses· 2
Related attack patterns· 1
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | External Control of Assumed-Immutable Web Parametercwe-472 | 100% | live |
| Weakness | Reliance on Cookies without Validation and Integrity Checkingcwe-565 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.