Threat DS.C.CDBSC-DST.4
URI: DS.C.CDBSC-DST.4
Package: ProcessComms
Description: Malicious query from Client via database Service leaks data Data : an attacker having the ability to send arbitrary queries to Service from or via Client injects a query to retrieve data Data. In this scenario, a selection query for Data would not be expected to come via Client, so the attack can be prevented using database access controls at Service.
Threat Type: Primary Threat