The Trends Report also details the vulnerabilities related to cloud and mobile device usage, noting a total of 89 mobile vulnerabilities were made public in 2011, while out of a set of 1201 publically reported vulnerabilities 855 had cloud based security implications. As mobile devices continue to be used to access online cloud computing platforms, emerging hybrid vulnerabilities haved developed as well. “The growing demand for cloud applications and mobile devices that access them is creating a unique problem,” continued Weinschenk. “Each has its own set of security issues, but when used in tandem, they can produce hybrid vulnerabilities that compound threats and increase the complexity of secure coding. By exploiting vulnerabilities in a mobile application a hacker can open up an attack vector to a preexisting vulnerability on the cloud based application, and vice versa.”
Key findings of the Cenzic Trends Report include: Web vulnerabilities
· In the first two months of 2012, 59 percent of all reported security vulnerabilities were Web vulnerabilities
· In 2011, Cross Site Scripting (XSS) accounted for 38 percent of total Web vulnerabilities
Mobile vulnerabilities
· A total of 89 mobile vulnerabilities were made public in 2011 and so far in 2012 (Jan-Feb) 11 mobile vulnerabilities have been made public.
· Sensitive Information Disclosure (28 percent) and Session Authentication and Authorization (28 percent) make up the bulk of the vulnerabilities.
Cloud vulnerabilities
· In 2011, out of a set of 1201 publically reported vulnerabilities 855 had cloud based security implications
· Specific security vulnerabilities were found in cloud-based applications including EyeOS, OrangeHRM, The Parallels Plesk Panel, Oracle Fusion Middleware, Batavi E Commerce, deV!ls ClanPortal, and more. To download a PDF version of the full report, please visit http://info.cenzic.com/2012-Applicaiton-Security-Trends-Report.html
Important Links
Cenzic Mobile Application Security Solution
About Cenzic
Cenzic provides the leading application security intelligence platform to continuously assess Cloud, Mobile and Web applications to reduce online security risk. Cenzic’s solutions scale from single applications to enterprise-level deployments with hybrid approaches that enable testing of applications at optimal levels. Cenzic helps brands of all sizes protect their reputation and manage security risk in the face of malicious attacks. Cenzic's solutions are used in all parts of the software development lifecycle, and most importantly in production, to protect against new threats even after the application has been deployed. Cenzic's application security intelligence platform is architected to handle web, cloud and mobile applications and is the first to provide risk reduction recommendations for business, application developers and specific applications. Today, Cenzic secures more than half a million online applications and trillions of dollars of commerce for Fortune 1000 companies, all major security companies, government agencies, universities and SMB companies.