CAPEC™ 57: Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
Description
This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and environment to obtain sensitive data once SSL is terminated.
Source: CAPEC™ 57
Related ASVS Requirements
ASVS (5.0): 10.1.1, 10.1.2, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.14, 10.5.4, 11.1.1, 11.1.2, 11.1.3, 11.1.4, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 13.1.4, 13.2.1, 13.2.2, 13.2.3, 13.2.4, 13.2.5, 13.3.1, 13.3.2, 13.3.3, 16.3.3, 9.1.1, 9.1.2, 9.1.3