Standardlikelihood: Highseverity: MediumDraft
CAPEC-39Manipulating Opaque Client-based Data Tokens
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
Medium
Description
In circumstances where an application holds important data client-side in tokens (cookies, URLs, data files, and so forth) that data can be manipulated. If client or server-side application components reinterpret that data as authentication tokens or data (such as store item pricing or wallet information) then even opaquely manipulating that data may bear fruit for an Attacker. In this pattern an attacker undermines the assumption that client side tokens have been adequately protected from tampering through use of encryption or obfuscation.
Related weaknesses· 9
Related attack patterns· 1
Exploits9
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Cleartext Storage of Sensitive Information in a Cookiecwe-315 | 100% | live |
| Weakness | Missing Support for Integrity Checkcwe-353 | 100% | live |
| Weakness | Session Fixationcwe-384 | 100% | live |
| Weakness | Reliance on Cookies without Validation and Integrity Checkingcwe-565 | 100% | live |
| Weakness | Improper Handling of Parameterscwe-233 | 100% | live |
| Weakness | External Control of Assumed-Immutable Web Parametercwe-472 | 100% | live |
| Weakness | Improper Authorizationcwe-285 | 100% | live |
| Weakness | Use of Persistent Cookies Containing Sensitive Informationcwe-539 | 100% | live |
| Weakness | Authentication Bypass by Assumed-Immutable Datacwe-302 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.