88 Percent of Java Apps Susceptible to Widespread Attacks

New Post Public Reply Private Reply Replies (0) Message Board
News Desk 2018
129
88 Percent of Java Apps Susceptible to Widespread Attacks from Known Security Defects, According to New Research from CA Veracode

BURLINGTON, MA--(Marketwired - Oct 18, 2017) - Veracode, Inc. , a leader in securing the world's software, and acquired by CA Technologies ( NASDAQ : CA ), today announced findings from the 2017 State of Software Security Report , a comprehensive review of application security testing data from scans conducted by CA Veracode's base of more than 1,400 customers. Among other industry trends such as vulnerability fix rates and percent of applications with vulnerabilities, the report exposes the pervasive risk from vulnerable open source components. The CA Veracode report found that 88 percent of Java applications contain at least one vulnerable component, making then susceptible to widespread attacks. This is in part because fewer than 28 percent of companies conduct regular composition analysis to understand which components are built into their applications.

"The universal use of components in application development means that when a single vulnerability in a single component is disclosed, that vulnerability now has the potential to impact thousands of applications -- making many of them breachable with a single exploit," said Chris Wysopal, CTO, CA Veracode.

Over the past 12 months, several high-profile breaches in Java applications were caused by widespread vulnerabilities in open source or commercial components. One example of a widespread component vulnerability was the " Struts-Shock " flaw disclosed in March 2017. According to the analysis, 68 percent of Java applications using the Apache Struts 2 library were using a vulnerable version of the component in the weeks following the initial attacks.

This critical vulnerability in the Apache Struts 2 library enabled remote code execution (RCE) attacks using command injection, for which as many as 35 million sites were vulnerable. Using this pervasive vulnerability, cybercriminals were able to exploit a range of victims' applications, most notably the Canada Revenue Agency and the University of Delaware. 

The 2017 State of Software Security Report also shows that approximately 53.3 percent of Java applications rely on a vulnerable version of the Commons Collections components. Even today, there are just as many applications using the vulnerable version as there were in 2016. The use of components in application development is common practice as it allows developers to reuse functional code -- speeding up the delivery of software. Studies show that up to 75 percent of a typical application's code is made up of open source components.

Wysopal continued, "development teams aren't going to stop using components -- nor should they. But when an exploit becomes available, time is of the essence. Open source and third party components aren't necessarily less secure than code you develop in-house, but keeping an up-to-date inventory of what versions of a component you are using. We've now seen quite a few breaches as a result of vulnerable components and unless companies start taking this threat more seriously, and using tools to monitor component usage, I predict the problem will intensify."

The use of vulnerable components is amongst the troubling application security trends examined in the State of Software Security Report. For example, CA Veracode's SoSS Report findings show that while many organizations prioritize fixing the most dangerous vulnerabilities, some still face challenges efficiently remediating software issues. Even the most severe flaws require significant time to fix (only 22 percent of very high severity flaws were patched in 30 days or less) and most attackers are leveraging vulnerabilities within days of discovery. Hackers and nation state organizations are given ample time to potentially infiltrate an enterprise network.

In addition to information regarding threat posed by the use of vulnerable components, the 2017 State of Software Security Report also found:

  • Vulnerabilities continue to crop up in previously untested software at alarming rates. 77 percent of apps have at least one vulnerability on initial scan.
  • Government organizations continue to underperform those in other industries. Not only did they have a 24.7 percent pass rate at latest scan, they also had the highest prevalence of highly exploitable vulnerabilities like cross-site scripting (49 percent) and SQL injection (32 percent).
  • Comparatively, between first and last scan, critical infrastructure had the strongest OWASP pass rate (29.8 percent) across all industries studied, though it saw a slight decline in pass rate (29.5 percent) on last scan. Two industries showing slight improvements between first and last scan include healthcare (27.6 percent vs. 30.2 percent) and retail & hospitality (26.2 percent vs. 28.5 percent). 

To download the full 2017 State of Software security report, please click here . To view the infographic, please click here .

Methodology Data for the eighth volume of CA Veracode's State of Software Security 2017 is derived from scans conducted by CA Veracode's base of 1,400+ customers, was drawn from code-level analysis of nearly 250 billion lines of code, across 400,000 assessments performed during the 12 month period from April 1, 2016 to March 31, 2017. The findings are representative of the application security industry's most comprehensive review of application testing data.

About CA Veracode CA Veracode enables the secure development and deployment of the software that powers the application economy. With its combination of automation, process and speed, CA Veracode becomes a seamless part of the software lifecycle, eliminating the friction that arises when security is detached from the development and deployment process. As a result, enterprises are able to fully realize the advantages of DevOps environments while ensuring secure code is synonymous with high-quality code.

CA Veracode serves more than 1,400 customers worldwide across a wide range of industries. The CA Veracode Platform has assessed more than 6 trillion lines of code and helped companies fix more than 27 million security flaws.

Learn more at www.veracode.com , on the CA Veracode blog and on Twitter .

Copyright © 2017 CA Veracode, Inc. All rights reserved. All other brand names, product names, or trademarks belong to their respective holders.

Contacts: Laura Paine Veracode Email Contact Phone: 339-674-1535 Megan Grasty Highwire for Veracode (U.S.) Email Contact Phone: 415-963-4174 ext. 26 Kate Baldwin Hotwire for Veracode (UK & EMEA) Email Contact Phone: +44 (0) 207 608 4677

Scroll down for more posts ▼

Top 10 Most Recent News Articles

MSP360 Unveils Free Proxmox Backup: A Game Changer?

Updated Category News Views 7

Backing Up: New Paths for Proxmox Users Ever get that feeling of uncovering something truly worth its weight in gold? That's what MSP360 just dropped on us, with their new backup solution for Proxmox that won’t cost you a dime upfront. They're calling it the Community Edition, and it’s not only free, but it comes with all the bells and whistles for protecting those...

Continue Reading
Orthopedic Expert Highlighting Midwest Pain Access Gaps

Updated Category News Views 5

Over in the vast sprawl of rolling plains and prairie winds, folks in the Upper Midwest are grappling with an ironic reality. As technological advancements blaze trails, people suffering from vertebrogenic pain are finding themselves up against a wall of limited access to specialized care. We’ve got Dr. James T. Brunz, the man of the hour, one of only about 15 Intracept...

Continue Reading
Mutare Sharpens Security for Webex Calls with Precision

Updated Category News Views 5

Control Dialed In: Tailored Call Screening Kicking things up a notch, Mutare is redefining call security by fine-tuning their Voice Security for Webex Calling. Imagine this—custom rules now let organizations shape a security policy down to the very last detail, ensuring unwanted calls don’t slip through the cracks. Wave goodbye to the broad-strokes approach. Precision...

Continue Reading
Robotics in Cleaning: 2026 Sees Double Adoption Rates

Updated Category News Views 4

Cleaning Industry Eyes Robotic Solutions Amid Labor Squeeze In a twist that's got industry veterans nodding knowingly, the cleaning industry is tipping towards automation. The recent 2026 Building Service Contractor Market Study reveals a massive leap: 32% of building service contractors (BSCs) plan to embrace robotic floor equipment in the coming year. That's a...

Continue Reading
WellLink Advisory Board Eyes Future of Healthcare Innovation

Updated Category News Views 3

Strategic Collaboration for Healthcare Evolution Ready to shake things up in healthcare, WellLink is setting the stage with its brand new Advisory Board. This move isn’t just about having fancy titles sitting around a conference table — it's about grabbing onto the future with both hands and figuring out just what the heck the healthcare industry needs next....

Continue Reading
CSS Revamps Identity, Emphasizing Senior Living Tech

Updated Category News Views 4

CSS Takes a Bold Step with a Fresh Brand Identity Every now and then, you see a company shake off the old coat and put on a polished new one. That's what CSS is doing with its updated brand, staking its claim as a heavyweight tech player in the senior living sector. No small feat, given the challenges stacked against these aging communities—tasked with keeping...

Continue Reading
Postal Connections Expands with New Hillsboro Opening

Updated Category News Views 8

Expanding Horizons in Hillsboro In the world of postal and office services, Annex Brands, Inc. is making headlines by launching yet another Postal Connections spot, this time planting its flag in the tech-centric town of Hillsboro, Oregon. Spearheaded by Jason Rautenkranz, this expansion is more than just another dot on a map—it's a strategic push into one of the...

Continue Reading
Cabot Wilds: Nova Scotia's Next Luxury Golf Haven

Updated Category News Views 7

Breaking New Ground in Golf and Luxury Cabot and the Bragg family are cooking up something extraordinary in Cumberland County, Nova Scotia. The new luxury lifestyle and golf destination, Cabot Wilds, promises to be more than just a retreat—it's a bold statement on how to marry nature, luxury, and community. Set to open in late 2027, this expansive 2,500-acre resort will...

Continue Reading
MasterBrand's 2027 Kitchen Trends: Embrace Warmth

Updated Category News Views 8

Wood Finishes and the Warm Embrace Alright folks, let's cut through the fluff and get to the heart of the matter: wood finishes are making a roaring comeback in 2027 kitchens. And it's not just some passing phase, we're talking a comprehensive shift toward warmer and more natural kitchen designs. MasterBrand, Inc. isn't just throwing darts at a board here. They surveyed a...

Continue Reading
NY Sheriffs' Court Battle: Immigration Policies Under Fire

Updated Category News Views 5

Sheriffs Clash with State Over Immigration Policies In a tense showdown reminiscent of an old-time standoff, 15 New York county sheriffs have drawn their battle lines against the state’s capricious maneuvers by pushing a federal court to hit the brakes on Albany’s newly minted immigration rule. The so-called “Local Cops, Local Crimes Act” is catching serious heat,...

Continue Reading

Top 5 Most Recently Viewed Articles

Innovative Concrete Testing Validates Premier Graphene's Advancements

Updated Category News Views 218

Premier Graphene Achieves Groundbreaking Testing Results Recently, a significant meeting took place between Pedro Mendez, President of Premier Graphene Inc., and representatives from a leading construction materials company. This exchange showcased the outstanding performance of Premier Graphene's innovative graphene-enhanced concrete, marking a noteworthy step forward in...

Continue Reading
Introducing V2CloudCare: Elevating Cloud Resilience and Innovation

Updated Category News Views 226

V2CloudCare: Redefining Cloud Resilience and Innovation V2 Cloud, renowned for its comprehensive cloud desktop, server, and application solutions, has unveiled an innovative new platform named V2CloudCare. This offering is set to transform the landscape of cloud resilience, VDI managed services, and cybersecurity, paving the way to effortless cloud computing experiences...

Continue Reading
AllianceBernstein Set to Announce Q3 2025 Results Soon

Updated Category News Views 163

AllianceBernstein's Upcoming Third Quarter 2025 Results AllianceBernstein L.P. and AllianceBernstein Holding L.P. (NYSE: AB) have exciting news! The financial details for the third quarter of 2025 are set to be unveiled soon. Investors and analysts alike are eagerly awaiting this important announcement, which is scheduled for release before markets open on Thursday,...

Continue Reading
Empowering Communities: Elizabeth R. Koch Foundation Grants

Updated Category News Views 543

Grant Opportunity Announcement for Nonprofits The Elizabeth R. Koch Foundation is excited to introduce its Request for Proposals (RFP) for the upcoming grant cycle. This initiative invites 501(c)(3) nonprofit organizations to apply for funding ranging from $25,000 to $50,000. The aim is to support those enterprises committed to enhancing the well-being of individuals...

Continue Reading
Advanced Medical Solutions Group plc: Recent Trading Insights

Updated Category News Views 188

Overview of Recent Trading Activities Trading activities can provide insightful perspectives on a corporation's market performance and its strategic maneuvers within the industry. Recently, Advanced Medical Solutions Group plc has witnessed notable dealings that merit discussion. Key Player and Role in the Market Investec Bank plc has been recognized as a significant...

Continue Reading