Detailedlikelihood: Highseverity: HighDraft
CAPEC-58Restful Privilege Elevation
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
An adversary identifies a Rest HTTP (Get, Put, Delete) style permission method allowing them to perform various malicious actions upon server data due to lack of access control mechanisms implemented within the application service accepting HTTP messages.
Metadata: detailed CAPEC pattern, status draft, likelihood high, severity high. Underlying weaknesses: CWE-267, CWE-269. Related CAPEC patterns: [object Object], [object Object].
Related weaknesses· 2
Related attack patterns· 2
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Privilege Managementcwe-269 | 100% | live |
| Weakness | Privilege Defined With Unsafe Actionscwe-267 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.