Standardlikelihood: Highseverity: Very HighStable
CAPEC-593Session Hijacking
Abstraction
Standard
Status
Stable
Likelihood
High
Severity
Very High
Description
This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to steal or manipulate an active session and use it to gain unathorized access to the application.
Metadata: standard CAPEC pattern, status stable, likelihood high, severity very high. Underlying weakness: CWE-287. Mapped ATT&CK techniques: [object Object], [object Object], [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 1
MITRE ATT&CK crosswalk· 3
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Authenticationcwe-287 | 100% | live |
Related to3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Browser Session Hijackingt1185 | 100% | live |
| SubTechnique | Application Access Tokent1550.001 | 100% | live |
| Technique | Remote Service Session Hijackingt1563 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.