What MITRE CAPEC-39: Manipulating Opaque Client-based Data Tokens (Standard Attack Pattern - Medium Severity) requires
MITRE CAPEC-39 (Manipulating Opaque Client-based Data Tokens) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In circumstances where an application holds important data client-side in tokens (cookies, URLs, data files, and so forth) that data can be manipulated. If client or server-side application components reinterpret that data as authentication tokens or data (such as store item pricing or wallet information) then even opaquely manipulating that data may bear fruit for an Attacker. Likelihood of attack: High. Typical severity: Medium. Parent pattern for CAPEC-31 Accessing/Intercepting/Modifying HTTP Cookies. Maps to weaknesses CWE-353, CWE-285, CWE-302, CWE-472, and others.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/39.html
SHA-256 integrity: 1f29db00a30dca14b1447e2aabe862290b9253608306a0366b7e3fe183ecc3cd
Primary Citations — 10 traced to source
- MITRE CAPEC-39: Manipulating Opaque Client-based Data Tokens (https://capec.mitre.org/data/definitions/39.html)
- CWE-353: underlying weakness (http://cwe.mitre.org/data/definitions/353.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-capec-capec-39-manipulating-opaque-client-based-data-tokens.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-capec-capec-39-manipulating-opaque-client-based-data-tokens.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-capec-capec-39-manipulating-opaque-client-based-data-tokens
- Back to registry: Browse all 10,085 compliance nodes