Detailedlikelihood: Mediumseverity: Very HighDraft
CAPEC-57Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
Very High
Description
This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and environment to obtain sensitive data once SSL is terminated.
Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity very high. Underlying weaknesses: CWE-300, CWE-287, CWE-693. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 3
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Authenticationcwe-287 | 100% | live |
| Weakness | Channel Accessible by Non-Endpointcwe-300 | 100% | live |
| Weakness | Protection Mechanism Failurecwe-693 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Network Sniffingt1040 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.