30 Marsh Wall,
E14 9TP London
+44 (1442) 245030
Web Application Vulnerabilities still on the Rise
Context publishes Web Application Vulnerability Statistics Report
Server misconfiguration and information-leakage topped the list of vulnerability categories that also included authentication, session management and authorisation weaknesses along with encryption vulnerabilities. The only exception to the upward trend was input validation weaknesses, most likely due to the increased use of frameworks that offer built-in input validation security features.
"While the number of vulnerabilities identified in applications from 2010 and 2011 has not increased greatly, it does indicate that developers are continuing to make the same mistakes and are still not addressing web app security sufficiently," says Michael Jordon, research and development manager at Context.
Web applications built for the Government sector were found to contain the highest number of vulnerabilities in 2011 and while the financial services sector had one of the lowest counts in 2010, this changed in 2011 with an average increase of roughly 1.5 vulnerabilities per web application tested. The law and insurance sector also saw similar results, seeing an average increase of roughly 2.5 vulnerabilities per web application penetration test in the same period.
"While some of the vulnerability categories such as server configuration and information leakage saw bigger rises, more serious cross-scripting and SQL injections present the biggest and potentially most damaging threats to web applications," says Context's Jordon. "Hopefully this document will provide help as a source of guidance, allowing developers and security professionals to prioritise and focus their web application security efforts in 2012. It is certainly clear that penetration testing before allowing a web application to go live is more relevant and essential than ever."
The full Web Application Vulnerability Statistics Report for 2010-2011 can be downloaded at: http://www.contextis.com/research/white-papers/WebApplicationVulnerabilityStatistics2010-2011/
The use of information published here for personal information and editorial processing is generally free of charge. Please clarify any copyright issues with the stated publisher before further use. In the event of publication, please send a specimen copy to email@example.com.