4. of Information Disclosure
An attacker can read content because messages (say, an email or HTTP cookie) aren’t encrypted even if the channel is encrypted.
Threat |
|
An administrator has access to the mailboxes on the server and can, therefore, read the content of your emails even though, between the sender and them arriving at your mailbox, they were transmitted over a secure channel. |
|
CAPEC |
CAPEC-180 - Exploiting Incorrectly Configured Access Control Security Levels |
ASVS |
8.3.5 - Ensure you have an audit trail for all sensitive data access. 8.3.7 - Use appropriate levels of encryption for the classification of the data. |
CWE |
CWE-312 - Cleartext Storage of Sensitive Information |