Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-51 — Poison Web Service Registry
CAPEC-51

Poison Web Service Registry

TLP:CLEAR

Description

Typical severity: Very High. Likelihood of attack: High. SOA and Web Services often use a registry to perform look up, get schema information, and metadata about services. A poisoned registry can redirect (think phishing for servers) the service requester to a malicious service provider, provide incorrect information in schema or metadata, and delete information about service provider interfaces.

Mitigation

Design: Enforce principle of least privilege | Design: Harden registry server and file access permissions | Implementation: Implement communications to and from the registry using secure protocols

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.