StandardDraft

CAPEC-277Data Interchange Protocol Manipulation

Abstraction
Standard
Status
Draft

Description

Data Interchange Protocols are used to transmit structured data between entities. These protocols are often specific to a particular domain (B2B: purchase orders, invoices, transport logistics and waybills, medical records). They are often, but not always, XML-based. Subverting the protocol can allow an adversary to impersonate others, discover sensitive information, control the outcome of a session, or perform other attacks. This type of attack targets invalid assumptions that may be inherent in implementers of the protocol, incorrect implementations of the protocol, or vulnerabilities in the protocol itself.

Related weaknesses· 1

CWE-707

Related attack patterns· 1

CAPEC-272 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessImproper Neutralizationcwe-707100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Protocol Manipulation
CAPEC
SOAP Manipulation
CAPEC
Web Services Protocol Manipulation
CAPEC
Client-Server Protocol Manipulation
CAPEC
Inter-component Protocol Manipulation
CAPEC
Spoofing of UDDI/ebXML Messages
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.