Umbra Wiki attack-pattern attack-pattern/CAPEC-179
Back to wiki

CAPEC-179 — Calling Micro-Services Directly

provenance: imported

CAPEC-179: Calling Micro-Services Directly

MITRE CAPEC attack pattern

Status Draft
Typical severity Medium
Likelihood of attack
Catalogue CAPEC 3.9 (2023-01-24)

Description

An attacker is able to discover and query Micro-services at a web location and thereby expose the Micro-services to further exploitation by gathering information about their implementation and function. Micro-services in web pages allow portions of a page to connect to the server and update content without needing to cause the entire page to update. This allows user activity to change portions of the page more quickly without causing disruptions elsewhere.

Prerequisites

  • The target site must use micro-services that interact with the server and one or more of these micro-services must be vulnerable to some other attack pattern.

Source