Compliance Node Overview
MITRE CAPEC-138 (Reflection Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary supplies a value to the target application which is then used by reflection methods to identify a class, method, or field. For example, in the Java programming language the reflection libraries permit an application to inspect, load, and invoke classes and their components by name. Likelihood of attack: Unknown. Typical severity: Very High. Maps to weaknesses CWE-470.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/138.html
SHA-256 integrity: be8697a7ab294157a205a96d676b8d6f6a749f251a27962b0b31dd69a87b44bf
Primary Citations — 7 traced to source
- MITRE CAPEC-138: Reflection Injection (https://capec.mitre.org/data/definitions/138.html)
- CWE-470: underlying weakness (http://cwe.mitre.org/data/definitions/470.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.