Detailedlikelihood: Highseverity: Very HighDraft
CAPEC-51Poison Web Service Registry
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
Very High
Description
SOA and Web Services often use a registry to perform look up, get schema information, and metadata about services. A poisoned registry can redirect (think phishing for servers) the service requester to a malicious service provider, provide incorrect information in schema or metadata, and delete information about service provider interfaces.
Related weaknesses· 3
Related attack patterns· 1
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Protection Mechanism Failurecwe-693 | 100% | live |
| Weakness | Improper Authorizationcwe-285 | 100% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.