Threat CC.R.CDBSC.4
URI: CC.R.CDBSC.4
Package: VulnerabilityCVSS
< prev | next >
Description: Query injection at Service into back end DB: an attacker having exploited a bug in Service when connected to DB, is able to send arbitrary queries to DB. This is modelled as an adverse behaviour in the inferred client channel representing their trust relationship, fulfilling the precondition for further threats using injected queries to access or alter data stored by DB.
Threat Type: Primary Threat