Click here to receive your FREE subscription to Campus Technology
5/13/2008
Organizations still aren't doing enough to protect their data from Web application vulnerabilities, according to a study released Tuesday by security firm Cenzic. The study, Application Security Trends Report, Q1 2008, identified "1,409 unique published vulnerabilities for the first quarter of 2008, with Web technology vulnerabilities comprising 70 percent of the vulnerability volume and 65 percent of the total vulnerabilities classified as easily exploitable," according to Cenzic.
According to the report, the most prevalent vulnerabilities were in the areas of information exposures/leaks, cross-site scripting, and "session management." Other highlights included:
"We're seeing many patterns over time, and our results remain consistent with the Symantec Internet Security Threat Report for the second half of 2007--that organizations are still not taking the proper initiatives to secure their Web applications," said Mandeep Khera, vice president of marketing at Cenzic, in a statement released to coincide with the report. "With organizations required to become compliant with PCI requirement 6.6 by June 30, they need to act aggressively. Many of these vulnerabilities are being discovered in the most commonly used commercial applications. However, most proprietary applications have even more vulnerabilities that are never fixed. PCI Compliance is important, however it's even more important to protect customer information by getting security vulnerabilities fixed in applications."
The vulnerabilities affected a wide range of technologies, from home-grown applications to commercial or publicly available technologies from Adobe, IBM, Microsoft, Sun, and others. The percentage of overall vulnerabilities stemming from Web applications remained consistent with reports dating back to early 2007, with each quarter hovering within two points of 70 percent.
Of these Web application vulnerabilities, 82 percent stemmed from the application itself; 12 percent were the fault of the Web server; 3 percent were attributable to Web browsers; and another 3 percent fell at the doorstep of media players.
The breakdown in vulnerabilities went something like this:
The complete study, with breakdowns of the top-10 specific vulnerabilities, is available for download from Cenzic's site in PDF format here.
About the author: Dave Nagel is the executive editor for 1105 Media's educational technology online publications and electronic newsletters. He can be reached at dnagel@1105media.com.
Have any additional questions? Want to share your story? Want to pass along a news tip? Contact Dave Nagel, executive editor, at dnagel@1105media.com.
copy text (above) for proper citation
In May in San Francisco, experts from leading universities, libraries, and research institutions around the world met as part of an ongoing effort to address a pressing issue: archiving the world's history, right up to today.
The Quilt, a coalition of 28 regional network organizations, has added XO Communications Services to its authorized vendor list. The Quilt represents 200 universities and thousands of other educational institutions across the United States. With this new relationship, Quilt members can purchase XO's high-speed IP transit and network transport services at competitive rates.
At the NECC 2008 conference in Texas this week, Wimba launched a new version of Wimba Classroom, the virtual classroom component of the company's Collaboration Suite. The new 5.2 release expands options for classroom capture and adds a variety of other functional and ease of use features.
The lure of automating workflow online so human intervention is minimized is continually reinforced in the minds of higher education administrators by examples of automated campus systems such as financials, student information systems, and other enterprise systems. But what's good for management is not always good for learning.
Cognos, which IBM acquired in January, has released an update to its business intelligence software that will run on the Linux operating system on IBM System z mainframes. IBM Cognos 8 BI was being developed by the two companies prior to the acquisition, but assimilation of Cognos into IBM accelerated development.
Facebook is a way to greet a colleague as if she or he is on your own campus: a wave at a distance, a hello at the corner burrito place, a honk as you both leave the campus parking lot. Informal collegiality has been extended over the miles.