Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-57 — Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
CAPEC-57

Utilizing REST's Trust in the System Resource to Obtain Sensitive Data

TLP:CLEAR

Description

Typical severity: Very High. Likelihood of attack: Medium. This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and environment to obtain sensitive data once SSL is terminated.

Mitigation

Implementation: Implement message level security such as HMAC in the HTTP communication | Design: Utilize defense in depth, do not rely on a single security mechanism like SSL | Design: Enforce principle of least privilege

Details

Platforms
Communications
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.