Detailedlikelihood: Lowseverity: MediumDraft
CAPEC-546Incomplete Data Deletion in a Multi-Tenant Environment
Abstraction
Detailed
Status
Draft
Likelihood
Low
Severity
Medium
Description
An adversary obtains unauthorized information due to insecure or incomplete data deletion in a multi-tenant environment. If a cloud provider fails to completely delete storage and data from former cloud tenants' systems/resources, once these resources are allocated to new, potentially malicious tenants, the latter can probe the provided resources for sensitive information still there.
Related weaknesses· 3
Related attack patterns· 1
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Access Controlcwe-284 | 100% | live |
| Weakness | Improper Scrubbing of Sensitive Data from Decommissioned Devicecwe-1266 | 100% | live |
| Weakness | Sensitive Information Uncleared Before Debug/Power State Transitioncwe-1272 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.