Detailedlikelihood: Highseverity: Very HighDraft

CAPEC-51Poison Web Service Registry

Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
Very High

Description

SOA and Web Services often use a registry to perform look up, get schema information, and metadata about services. A poisoned registry can redirect (think phishing for servers) the service requester to a malicious service provider, provide incorrect information in schema or metadata, and delete information about service provider interfaces.

Related weaknesses· 3

CWE-285CWE-74CWE-693

Related attack patterns· 1

CAPEC-203 (ChildOf)

Exploits3

TypeTargetConfidenceTier
WeaknessProtection Mechanism Failurecwe-693100%live
WeaknessImproper Authorizationcwe-285100%live
WeaknessImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Schema Poisoning
CAPEC
XML Schema Poisoning
CAPEC
DNS Cache Poisoning
CAPEC
Cache Poisoning
CAPEC
Web Services Protocol Manipulation
CAPEC
Manipulate Registry Information
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.