Typical severity: Very High. Likelihood of attack: Medium. This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and environment to obtain sensitive data once SSL is terminated.
Implementation: Implement message level security such as HMAC in the HTTP communication | Design: Utilize defense in depth, do not rely on a single security mechanism like SSL | Design: Enforce principle of least privilege