Platform & Code (PCJ)
Platform & Code
J
Johan can modify or expose sensitive data by exploiting weaknesses in the SDK or third party libraries because updates to the app and platform are not enforced or do not patch known software vulnerabilities
Scenario: Johan can modify or expose sensitive data by exploiting weaknesses in the SDK or third party libraries because updates to the app and platform are not enforced or do not patch known software vulnerabilities
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
OWASP MASVS: CODE-1,CODE-2,CODE-3
OWASP MASTG: TEST-0036,TEST-0042,TEST-0080,TEST-0085
SAFECode: -
Attacks
No attacks registered!