THE CENZIC BLOG
Read more articles in  Web Application Security Insights
.
November 10, 2009

Web Application Security Trends Report: Q1-Q2 2009

Read the latest Web application security trends from January – June 2009

Web application securityWant to read about the latest trends and stats in the Web application security world?  Then look no further – we’ve just issued our latest report for the first half of 2009.

You can read all the gooey details in the report, but here are some key findings worth highlighting:  

  • Sun Java, PHP, and Apache continue to be among the Top 10 vendors having the most severe vulnerabilities for the first half of 2009
  • 78% of the total reported vulnerabilities affected Web technologies, such as Web servers, applications, Web browsers.  Plugins and ActiveX, which is a significant increase from earlier in the year.
  • Of the browser vulnerabilities, the biggest surprise was Firefox that had 44% more vulnerabilities than the other browsers.  Another surprise was Safari – as it usually contains few vulnerabilities, but came in at 35%; significantly higher than Internet Explorer (15%).
  • Based on the vulnerabilities found using Cenzic’s managed service – ClickToSecure – Information Leaks, XSS, Authentication / Authorization and Session Management flaws continue to dominate
  • The majority of assessments completed by Cenzic had a high HARM score, highlighting the continuing risk and exposure faced by organizations

Happy reading!

by
Erin Swanson
Eswanson@cenzic.com

Comments
.

RE: Web Application Security Trends Report: Q1-Q2 2009

Source of browser vulnerability report
What are your sources for the browser vulnerabilities?
.
Note: 3 comments pending moderation

Syndication OptionsRSS (Rich Site Summary) Feed Atom Feed OPML (Outline Processor Language) Feed MYST-ML (MyST Markup Language) Content Feed MS-Office Smart Tag Subscription