Detailedlikelihood: Highseverity: HighDraft
CAPEC-59Session Credential Falsification through Prediction
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
This attack targets predictable session ID in order to gain privileges. The attacker can predict the session ID used during a transaction to perform spoofing and session hijacking.
Metadata: detailed CAPEC pattern, status draft, likelihood high, severity high. Underlying weaknesses: CWE-290, CWE-330, CWE-331, CWE-346, CWE-488 (and 6 more). Related CAPEC pattern: [object Object].
Related weaknesses· 11
Related attack patterns· 1
Exploits11
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Session Fixationcwe-384 | 100% | live |
| Weakness | Authentication Bypass by Spoofingcwe-290 | 100% | live |
| Weakness | Use of Persistent Cookies Containing Sensitive Informationcwe-539 | 100% | live |
| Weakness | Exposure of Data Element to Wrong Sessioncwe-488 | 100% | live |
| Weakness | Protection Mechanism Failurecwe-693 | 100% | live |
| Weakness | Improper Authorizationcwe-285 | 100% | live |
| Weakness | J2EE Misconfiguration: Insufficient Session-ID Lengthcwe-6 | 100% | live |
| Weakness | Use of Insufficiently Random Valuescwe-330 | 100% | live |
| Weakness | Exposure of Sensitive Information to an Unauthorized Actorcwe-200 | 100% | live |
| Weakness | Insufficient Entropycwe-331 | 100% | live |
| Weakness | Origin Validation Errorcwe-346 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.