Compliance Node Overview
MITRE CAPEC-109 (Object Relational Mapping Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages a weakness present in the database access layer code generated with an Object Relational Mapping (ORM) tool or a weakness in the way that a developer used a persistence framework to inject their own SQL commands to be executed against the underlying database. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-20, CWE-89, CWE-564.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/109.html
SHA-256 integrity: c388f31dff26fa85ce1be9245bdebaceaa54f17517e6ecbef0d4040069613555
Primary Citations — 10 traced to source
- MITRE CAPEC-109: Object Relational Mapping Injection (https://capec.mitre.org/data/definitions/109.html)
- CWE-20: underlying weakness (http://cwe.mitre.org/data/definitions/20.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.