CAPEC-58: Restful Privilege Elevation

An adversary identifies a Rest HTTP (Get, Put, Delete) style permission method allowing them to perform various malicious actions upon server data due to lack of access control mechanisms implemented within the application service accepting HTTP messages.

Severity
High
Likelihood
High
7
/ 100
low-risk
Active Threat 5/50 · Minimal
Exploit Availability 2/50 · Minimal