Vulnerabilities / Threats

09:45 AM
Dark Reading
Dark Reading
Products and Releases

Survey: Most Enterprises Don't Fix 60 Percent of Security Vulnerabilities

More than half take three Months to remediate flaws, according to a joint survey by Waratek at Gartner Security and Risk Management Summit

NEW YORK – June 25, 2015 – Waratek, the application protection and management company, today announced the results of a survey conducted at the Gartner Security and Risk Management Summit 2015. Two-thirds of senior security professionals polled said they remediate 40 percent or less of the security vulnerabilities discovered by software application security testing (SAST) tools. Meanwhile, 50 percent of respondents reported that it takes their organization three months (23%) or more (27%) to fix security flaws in their applications.

“We expected the number of known vulnerabilities being fixed by enterprises would be low, but were surprised by the sheer volume that are never addressed. The amount of time it takes to remediate those that are being corrected was even more disturbing,” said Brian Maccaba, CEO of Waratek. “The fact that software application security testing tools are unable to remediate the vulnerabilities they detect is a major reason why organizations are only able to fix 40 percent or less of the flaws they know exist.”

Survey Findings

Waratek surveyed more than 100 security executives and professionals at the recent Gartner Security and Risk Management Summit about their application security testing and remediation practices. According to those polled:

•         The majority (52%) of enterprises test less than half of their applications with SAST tools. More than one third (37%) test less than 20% percent of the applications for vulnerabilities.

•         One-third (36%) of enterprises fix 40% of the vulnerabilities discovered by their SAST tools. Nearly one-third (29%) fix less than 20% of security flaws they know exist.

•         It takes half (50%) of enterprises three months or more to fix security vulnerabilities after they are discovered by SAST tools. Only 11% fix flaws in two weeks or less.


Last week, Waratek announced that it has developed the ability for its runtime application self-protection (RASP) product to consume CWE (common weakness enumeration) reports from SAST tools like HP Fortify, Veracode, Checkmarx and others to generate rules that immediately address application security vulnerabilities. This fully automated workflow can immediately protect production applications without any manual intervention or configuration. It can also be integrated into the Software Development Lifecycle. Using a closed-loop process, Waratek AppSecurity for Java provides validation to SAST/DAST tools that vulnerabilities have been remediated.

About Waratek

Waratek makes enterprise apps more secure and easier to manage. Waratek AppSecurity for Java and Waratek Locker provide transparent, runtime application self-protection in datacenter and cloud environments, respectively. Waratek CloudVM enables multiple Java apps to be deployed on a single server for dramatically reduced operating costs. The company was chosen as the Most Innovative Company at RSA Conference 2015, is a SWIFT Innotribe Top Global Innovator and FinTech Innovation Lab winner. Waratek is headquartered in Dublin, Ireland with subsidiaries in New York and London, and offices in Sydney, Tokyo, Shanghai, Taipei and Seoul. For further information please visit


Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Who Does What in Cybersecurity at the C-Level
Steve Zurier, Freelance Writer,  3/16/2018
New 'Mac-A-Mal' Tool Automates Mac Malware Hunting & Analysis
Kelly Jackson Higgins, Executive Editor at Dark Reading,  3/14/2018
(ISC)2 Report: Glaring Disparity in Diversity for US Cybersecurity
Kelly Jackson Higgins, Executive Editor at Dark Reading,  3/15/2018
Register for Dark Reading Newsletters
White Papers
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.