COMMON ATTACK PATTERN ENUMERATION AND CLASSIFICATIONLive MITRE record
CAPEC-109
Object Relational Mapping Injection
Abstraction
Detailed
Typical severity
High
Likelihood of attack
Low
Understand the attack
What is this attack pattern?
Execution flow
How does the attack proceed, step by step?
Explore
Determine Persistence Framework Used
Techniques used
Probe for ORM Injection vulnerabilities
Exploit
Perform SQL Injection through the generated data access layer
Techniques used
Requirements
What does the attack require?
Prerequisites
Skills required
Resources required
Impact
What does a successful attack lead to?
Modify Data
Unreliable Execution
Read Data
Gain Privileges
Execute Unauthorized Commands
Defence
How is it prevented and mitigated?
1
2
Real world