CAPEC™ 212: Functionality Misuse
Description
An adversary leverages a legitimate capability of an application in such a way as to achieve a negative technical impact. The system functionality is not altered or modified but used in a way that was not intended. This is often accomplished through the overuse of a specific functionality or by leveraging functionality with design flaws that enables the adversary to gain access to unauthorized, sensitive data.
Source: CAPEC™ 212
Related ASVS Requirements
ASVS (5.0): 15.3.1, 15.3.3, 15.4.1, 15.4.2, 16.3.2, 16.3.3, 2.1.3, 2.2.1, 2.2.2, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.4.1, 2.4.2, 3.5.7, 8.1.1, 8.1.2, 8.2.1, 8.2.2, 8.2.3, 8.3.1