CAPEC 51 Poison Web Service Registry

Draft Detailed High Risk
Severity Very High

Description

SOA and Web Services often use a registry to perform look up, get schema information, and metadata about services. A poisoned registry can redirect (think phishing for servers) the service requester to a malicious service provider, provide incorrect information in schema or metadata, and delete information about service provider interfaces.

Attack Execution Flow

4

Mitigations

3

Consequences

Relationships

Resources Required

1