Standardlikelihood: Mediumseverity: HighDraft
CAPEC-231Oversized Serialized Data Payloads
Abstraction
Standard
Status
Draft
Likelihood
Medium
Severity
High
Description
An adversary injects oversized serialized data payloads into a parser during data processing to produce adverse effects upon the parser such as exhausting system resources and arbitrary code execution.
Metadata: standard CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-112, CWE-20, CWE-674, CWE-770. Related CAPEC pattern: [object Object].
Related weaknesses· 4
Related attack patterns· 1
Exploits4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Missing XML Validationcwe-112 | 100% | live |
| Weakness | Allocation of Resources Without Limits or Throttlingcwe-770 | 100% | live |
| Weakness | Uncontrolled Recursioncwe-674 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.