What API6:2023 Unrestricted Access to Sensitive Business Flows requires
OWASP API Security Top 10 (2023) API6:2023 Unrestricted Access to Sensitive Business Flows. When creating an API Endpoint, it is important to understand which business flow it exposes. Some business flows are more sensitive than others, in the sense that excessive access to them may harm the business. Common examples of sensitive business flows and risk of excessive access associated with them: * Purchasing a product flow - an attacker can buy all the stock of a high-demand item at once and resell for a higher price (scalping) * Creating a comment/post flow - an attacker can spam the system * Making a reservation - an attacker can reserve all the available time slots and prevent other users from using the system The risk of excessive access might change between industries and businesses. For example - creation of posts by a script might be considered as a risk of spam by one social network, but encouraged by another social network. An API Endpoint is vulnerable if it exposes a sensitive business flow, without appropriately restricting the access to it. This category sits within the OWASP API Security Top 10 (2023 edition), the canonical industry list of the ten most critical API security risks. Organizations implementing API services should treat each of the ten categories as both a design constraint and a continuous-monitoring obligation, with policies, automated testing, and incident response procedures defined per category.
Pillar: Cybersecurity · Authority: OWASP Foundation (Open Worldwide Application Security Project) · Version: 1.0.0 · Last updated:
Primary source: https://owasp.org/API-Security/editions/2023/en/0xa6-unrestricted-access-to-sensitive-business-flows/
SHA-256 integrity: 5bffe8f4e0075a53c1d99ccac5bf5d0857bc8b961eb03767d84fff24c6faafaa
Primary Citations — 9 traced to source
- OWASP API Security Top 10 (2023), API06:2023 Unrestricted Access to Sensitive Business Flows, How To Prevent: 'Business - identify the business flows that might harm the business if they are excessively used.'
- OWASP API Security Top 10 (2023), API06:2023 Unrestricted Access to Sensitive Business Flows, How To Prevent: 'Engineering - choose the right protection mechanisms to mitigate the business risk.'
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/owasp-api-top-10-2023-api06-unrestricted-access-to-sensitive-business-flows.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/owasp-api-top-10-2023-api06-unrestricted-access-to-sensitive-business-flows.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/owasp-api-top-10-2023-api06-unrestricted-access-to-sensitive-business-flows
- Back to registry: Browse all 10,090 compliance nodes