David can bypass the application to gain access to data because the network and host infrastructure, and supporting services/applications, have not been securely configured, the configuration rechecked periodically and security patches applied, or the data is stored locally, or the data is not physically protected
David can bypass the application to gain access to data because the network and host infrastructure, and supporting services/applications, have not been securely configured, the configuration rechecked periodically and security patches applied, or the data is stored locally, or the data is not physically protected
OWASP SCP
151,152,156,160,161,173,174,175,176,177
OWASP ASVS
1.4.5,10.3.1,10.3.2,14.1.4,14.1.5,14.2.1,14.2.2
OWASP AppSensor
RE1,RE2
CAPEC
-
SAFECODE
NB: The key concept for this card is host/network hardening, configuration and patching. See C 10 instead for software hardening, configuration and patching.
OWASP ASVS (4.0): 1.4.5 ,10.3.1 ,10.3.2 ,14.1.4 ,14.1.5 ,14.2.1 ,14.2.2
OWASP SCP: 151,152,156,160,161,173,174,175,176,177
OWASP Appsensor: RE1,RE2
Safecode:
ASVS V1.4 - Access Control Architectural Requirements
ASVS V10.3 - Deployed Application Integrity Controls
No suitable mappings were found.