{
  "node_id": "mitre-capec-capec-110-sql-injection-through-soap-parameter-tampering",
  "title": "MITRE CAPEC-110: SQL Injection through SOAP Parameter Tampering (Detailed Attack Pattern - Very High Severity)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE CAPEC-110 (SQL Injection through SOAP Parameter Tampering) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker modifies the parameters of the SOAP message that is sent from the service consumer to the service provider to initiate a SQL injection attack. On the service provider side, the SOAP message is parsed and parameters are not properly validated before being used to access a database in a way that does not use parameter binding, thus enabling the attacker to control the structure of the executed SQL query. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-89, CWE-20.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_attack"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "iso-27001-2022",
    "cis-controls-v8",
    "owasp-asvs-l2"
  ],
  "primary_citations_count": 8
}