Standardlikelihood: Lowseverity: MediumDraft
CAPEC-528XML Flood
Abstraction
Standard
Status
Draft
Likelihood
Low
Severity
Medium
Description
An adversary may execute a flooding attack using XML messages with the intent to deny legitimate users access to a web service. These attacks are accomplished by sending a large number of XML based requests and letting the service attempt to parse each one. In many cases this type of an attack will result in a XML Denial of Service (XDoS) due to an application becoming unstable, freezing, or crashing.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 2
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Allocation of Resources Without Limits or Throttlingcwe-770 | 100% | live |
Related to2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Direct Network Floodt1498.001 | 100% | live |
| SubTechnique | Service Exhaustion Floodt1499.002 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.