Home > Study: Top Web Application Vulnerabilities Remain Unfixed

News

Study: Top Web Application Vulnerabilities Remain Unfixed

5/13/2008

Organizations still aren't doing enough to protect their data from Web application vulnerabilities, according to a study released Tuesday by security firm Cenzic. The study, Application Security Trends Report, Q1 2008, identified "1,409 unique published vulnerabilities for the first quarter of 2008, with Web technology vulnerabilities comprising 70 percent of the vulnerability volume and 65 percent of the total vulnerabilities classified as easily exploitable," according to Cenzic.

According to the report, the most prevalent vulnerabilities were in the areas of information exposures/leaks, cross-site scripting, and "session management." Other highlights included:

"We're seeing many patterns over time, and our results remain consistent with the Symantec Internet Security Threat Report for the second half of 2007--that organizations are still not taking the proper initiatives to secure their Web applications," said Mandeep Khera, vice president of marketing at Cenzic, in a statement released to coincide with the report. "With organizations required to become compliant with PCI requirement 6.6 by June 30, they need to act aggressively. Many of these vulnerabilities are being discovered in the most commonly used commercial applications. However, most proprietary applications have even more vulnerabilities that are never fixed. PCI Compliance is important, however it's even more important to protect customer information by getting security vulnerabilities fixed in applications."

The vulnerabilities affected a wide range of technologies, from home-grown applications to commercial or publicly available technologies from Adobe, IBM, Microsoft, Sun, and others. The percentage of overall vulnerabilities stemming from Web applications remained consistent with reports dating back to early 2007, with each quarter hovering within two points of 70 percent.

Of these Web application vulnerabilities, 82 percent stemmed from the application itself; 12 percent were the fault of the Web server; 3 percent were attributable to Web browsers; and another 3 percent fell at the doorstep of media players.

The breakdown in vulnerabilities went something like this:

The complete study, with breakdowns of the top-10 specific vulnerabilities, is available for download from Cenzic's site in PDF format here.



About the author: Dave Nagel is the executive editor for 1105 Media's educational technology online publications and electronic newsletters. He can be reached at dnagel@1105media.com.

Have any additional questions? Want to share your story? Want to pass along a news tip? Contact Dave Nagel, executive editor, at dnagel@1105media.com.

Cite this Site

David Nagel, "Study: Top Web Application Vulnerabilities Remain Unfixed," Campus Technology, 5/13/2008, http://www.campustechnology.com/article.aspx?aid=62579

copy text (above) for proper citation



Recommended Reading
  • California Community Colleges Partner with Waterfall Mobile on Statewide Emergency Notification Coverage

    The Foundation for California Community Colleges (FCCC) has awarded a statewide emergency alert notification contract to Waterfall Mobile. The contract establishes Waterfall's AlertU as an approved technology through the official non-profit foundation for the California Community College (CCC) system office. Through this partnership, individual colleges may directly implement emergency communication services, eliminating lengthy technology evaluation and RFP processes.

  • King's College and ASU Add e2Campus for Improved Emergency Notifications

    King's College and Arizona State University have switched to Omnilert's e2Campus for emergency notification. Omnilert also has introduced a new program called the ENS Conversion Service that allows schools to bulk upload data from their previous emergency notification system into e2Campus at no charge.

  • Saint Joseph Builds Out Wireless Network in Multi-year Upgrade

    Saint Joseph's University has begun deploying a Meru Networks wireless local area network across its Philadelphia campus as part of a multi-year effort to bring wireless coverage to every building on campus.

  • Vista Ramp Up Is Happening Now, Study Says

    Organizations may have been slow to adopt Microsoft Windows Vista, but expect that to change by late 2008 to 2009, according to a Forrester Research report by Benjamin Gray et al., published last week.

  • Talisma Launches New Version of CRM with Built-in Application Management

    Talisma Corp. announced version 8.0 of its constituent relationship management (CRM) application for higher education. The new release includes application management, a revamped user interface, two-way text messaging, personalized Web portals, and an ADA-compliant Web client, among other enhancements.

  • Bringing Composers into Classrooms Through Skype

    Two Pennsylvania teaching colleagues with an interest in music and technology are bringing remote experts into classrooms at almost no cost, using Skype's free videoconferencing technology.