VRB News
Virtual Reality Brisbane
  • Home
  • About us
  • IT news
  • Tech
  • World
  • Contact
No Result
View All Result
  • Home
  • About us
  • IT news
  • Tech
  • World
  • Contact
No Result
View All Result
No Result
View All Result
Home IT news

Security vulnerabilities in almost 90 percent of all Java applications

admin by admin
March 18, 2021
in IT news
0
0
SHARES
42
VIEWS
Share on FacebookShare on Twitter

This is one of the CA VeraCode published report State of Software Security (SOSS) 2017. Thus, 88% of applications contain at least one vulnerable component. 53 percent of Java applications to build even on a component, which is a gap with the CVE ID vulnerable.

The use of Open-Source components for Java applications brings with it some significant risks. This basically affects thousands of daily-used programs. This is from the current edition of the State of Software Security (SOSS) 2017 by CA VeraCode.

code monitor (image: Shutterstock)

The report of the in the spring of CA Technologies acquired specialists, according to the Java applications are in 88 percent of one or more of the components used for attacks. And 53 percent of Java applications based even on Code that already in the CVE-chess database captured gap’s.

The reason is the frequent, especially the re-use of Java components. As a result, the developers move faster and make your work easier. According to the CA Veracode can put together up to 75 percent of an application’s code of Open Source components. There is also the risk that contained or discovered vulnerabilities elsewhere in the components used are not closed-but – either because there is not more to you is meant to be or because they are not known.

Veracode (Graphic: Rating Code)

This is also the CA VeraCode staff and silicon has already recently.de-Blogger Julian Totzek-hall Huber pointed out. Not only for developers, will make the work easier for cyber criminals: “If a single Open-Source component found in thousands of applications have their place, must not planned an attack for each individual Software and be done, but only the component used to target. Thousands of applications at a stroke,” says Totzek-Hallhuber in silicon.de.

His company refers, in the context of the problems in the spring made available a Patch for Apache Struts. Since the gap has not been closed in all of the programs immediately, the use of this block, there were an estimated between 30 and 35 million sites about it vulnerable to attack.

The eighth edition of the Veracode report is based on over 400,000 Code-analysis, and to 250 billion studied lines of Code. In the last twelve months, 12.8 million error had been discovered as a result. According to the report, only 28 percent of companies perform an analysis to identify the building blocks of your Software and to keep in view. For this task, CA VeraCode has been offering its tools and services.

Github and Black Duck active

The competition has been getting recently from Github. The platform allows to determine the current, at least in the case of applications based on Javascript and Ruby dependencies of various components, and to identify new and even security vulnerabilities in the program components.

Already active for a longer time, the U.S. company Black Duck is in the area. The can identify with its technology also used the Open-Source Code and its correct mapping to automate. As a result, only known security gaps reveal, but also to license issues. Such skills are also displays of the purchase of Black Duck by Synopsys. The buyer who can offer security testing of Software in General, as well as integrated Circuits, paid for the additional Expertise and technology 565 million dollars. The transaction is expected to be in the course of the year 2017 completed.

Previous Post

From Java EE to Jakarta marks the restart

Next Post

PSVR 2: presents a new controller for the PS5 VR

admin

admin

Related Posts

How to Grow a YouTube Channel with ScaleLab
IT news

How to Grow a YouTube Channel with ScaleLab: Effective Strategies for Creators

February 4, 2025
Sticker mockups
IT news

Sticker mockups: how to visualize your ideas professionally and efficiently

January 13, 2025
Ways to Get Free Senegal Proxies for Work and Surfing
IT news

Ways to Get Free Senegal Proxies for Work and Surfing

December 24, 2024
Crypto Betting Frontiers
IT news

Crypto Betting Frontiers: The 2025 Landscape

December 6, 2024
iGaming Marketing Trends for 2025
IT news

iGaming Marketing Trends for 2025: Adapting to a Rapidly Changing Landscape

December 5, 2024
Next Post
PSVR 2: presents a new controller for the PS5 VR

PSVR 2: presents a new controller for the PS5 VR

Premium Content

Facebook began to mark the publication of controlled States media

Facebook began to mark the publication of controlled States media

June 13, 2020
Mova — Autonomous VR glasses from the former head HTC

Mova — Autonomous VR glasses from the former head HTC

August 15, 2020
Magic Leap opens a new center in Switzerland to boost its technology

Magic Leap opens a new center in Switzerland to boost its technology

January 21, 2022

Browse by Category

  • Games
  • IT news
  • Tech
  • World

VRB News is ready to cooperate with webmasters and content creators. Send an email to info@virtualrealitybrisbane.com

Categories

  • Games
  • IT news
  • Tech
  • World

Recent Posts

  • How to Grow a YouTube Channel with ScaleLab: Effective Strategies for Creators
  • Sticker mockups: how to visualize your ideas professionally and efficiently
  • Ways to Get Free Senegal Proxies for Work and Surfing

© 2023 - The project has been developed ServReality

No Result
View All Result
  • Home
  • About us
  • IT news
  • Tech
  • World
  • Contact

© 2023 - The project has been developed ServReality

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?