Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-278 — Web Services Protocol Manipulation
CAPEC-278

Web Services Protocol Manipulation

TLP:CLEAR

Description

An adversary manipulates a web service related protocol to cause a web application or service to react differently than intended. This can either be performed through the manipulation of call parameters to include unexpected values, or by changing the called function to one that should normally be restricted or limited. By leveraging this pattern of attack, the adversary is able to gain access to data or resources normally restricted, or to cause the application or service to crash.

Mitigation

Design: Range, size and value and consistency verification for any arguments supplied to applications and services from external sources and devise appropriate error response. | Design: Ensure that function calls that should not be called by an unprivileged user are not accessible to them.

Details

Platforms
Communications
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.