What MITRE CAPEC-493: SOAP Array Blowup (Standard Attack Pattern) requires
MITRE CAPEC-493 (SOAP Array Blowup) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute an attack on a web service that uses SOAP messages in communication. By sending a very large SOAP array declaration to the web service, the attacker forces the web service to allocate space for the array elements before they are parsed by the XML parser. Likelihood of attack: Unknown. Maps to weaknesses CWE-770.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/493.html
SHA-256 integrity: 9c584cde2fc91cf758ac61c588b0e320ac28c1166436e3cb4089078b7979d64f
Primary Citations — 7 traced to source
- MITRE CAPEC-493: SOAP Array Blowup (https://capec.mitre.org/data/definitions/493.html)
- CWE-770: underlying weakness (http://cwe.mitre.org/data/definitions/770.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.