1. https://appdevelopermagazine.com/security
  2. https://appdevelopermagazine.com/whitehat-web-applications-security-statistics-report-highlights-chronic-vulnerabilities/
6/12/2016 3:02:25 PM
WhiteHat Web Applications Security Statistics Report Highlights Chronic Vulnerabilities
Web Applications Security,Transport Layer Protection,Cross-Site Scripting
/Whitehat-Security-App-Developer-Magazine_he6le7ho.jpg
App Developer Magazine
WhiteHat Web Applications Security Statistics Report Highlights Chronic Vulnerabilities

Security

WhiteHat Web Applications Security Statistics Report Highlights Chronic Vulnerabilities


Sunday, June 12, 2016

Stuart Parkerson Stuart Parkerson


WhiteHat Security has released its eleventh annual Web Applications Security Statistics Report which was compiled using data collected from tens of thousands of websites to analyze vulnerabilities, remediation rates and risk levels. The report reveals that on average, the majority of web applications exhibit two or more serious vulnerabilities per application for every industry at any given point in time.

The report’s findings are based on the aggregated vulnerability scanning and remediation data from web applications that use the WhiteHat Sentinel service for security testing. The research shows of the 12 industries analyzed in the report, the information technology (IT), education, and retail industries suffer the highest number of critical or high-risk vulnerabilities per web application, at 17, 15 and 13 respectively.

The findings also highlight that the IT and retail industries struggle to remediate in a timely manner. It takes approximately 250 days for IT and 205 days for retail businesses to fix the software flaws. Additionally, highly regulated industries, such as financial services and healthcare, are not performing significantly better than the rest.

Other findings from the report:


- Since 2013, the average time to fix vulnerabilities has trended upward; in 2013, the average time-to-fix was approximately 100 days. The average time-to-fix in 2015 jumped to approximately 150 days,

- Critical and high-risk vulnerabilities have an average age of 300 and 500 days, respectively.

- For the 12 industries analyzed in the report, nine have vulnerability remediation rates below 50 percent.

- Insufficient Transport Layer Protection, Information Leakage and Cross-Site Scripting are widely known application vulnerabilities, yet they are the three most common vulnerabilities found within web applications across all industries.

White Hat will host a webinar on June 29 at 10am PDT to review and discuss the findings. The full report is available at the link below.


Read more: https://info.whitehatsec.com/Website-Stats-Report-...




Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


Tether QVAC SDK Powers AI Across Devices and Platforms
Tether QVAC SDK Powers AI Across Devices and Platforms Wednesday, April 22, 2026


APAC 5G expansion to fuel 347B mobile market by 2030
APAC 5G expansion to fuel 347B mobile market by 2030 Tuesday, April 21, 2026




How AI is causing app litter everywhere
How AI is causing app litter everywhere Tuesday, April 21, 2026


The App Economy Is Thriving
The App Economy Is Thriving Monday, April 20, 2026


NIKKE 3.5 anniversary update livestream coming soon
NIKKE 3.5 anniversary update livestream coming soon Friday, April 17, 2026


New AI tool targets early dementia detection
New AI tool targets early dementia detection Thursday, April 16, 2026


Jentic launch gives AI agents api access
Jentic launch gives AI agents api access Wednesday, April 15, 2026


Experts warn ai-generated health content risks misinterpretation without human oversight
Experts warn ai-generated health content risks misinterpretation without human oversight Wednesday, April 15, 2026


Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines
Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines Tuesday, April 14, 2026


AccuWeather Launches ChatGPT Integration for Live Weather Updates
AccuWeather Launches ChatGPT Integration for Live Weather Updates Tuesday, April 14, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>