13.07.2015 Views

hp-security-research-cyber-risk-report-pdf-2-w-1408

hp-security-research-cyber-risk-report-pdf-2-w-1408

hp-security-research-cyber-risk-report-pdf-2-w-1408

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

HP Security Research | Cyber Risk Report 2015Cookie <strong>security</strong> and system information leakage continue to be prominent issues whencompared to 2013’s trends. Due to recent changes to the HP Software Security Taxonomy,access control issues have now been merged into the greater Web Server Misconfigurationgroup. With this in mind, misconfiguration issues gained the top spot based on 2014 data.Interestingly, Transport Layer Protection (now called Insecure Transport) and Cross-SiteScripting moved down to seventh and eighth places respectively. These were replaced byPrivacy Violation and Cross-Frame Scripting. The HP Cyber Risk Report released in 2013performed a detailed analysis of defenses against cross-frame scripting. Two years later, HPSRcontinues to find this to be a prevalent issue across Web applications.Top 10 Web application vulnerabilitiesEach category within the taxonomy may be further refined based on specific characteristics ofthe vulnerability. The chart below represents the most prevalent Web application vulnerabilitiesseen in 2014.Figure 21. Top 10 common vulnerabilities discovered in Web applications in 2014Cross-frame scripting 48%Web server misconfiguration: Unprotected filePrivacy violation: AutocompleteWeb server misconfiguration: Unprotected directoryCookie <strong>security</strong>: HTTPOnly not set47%46%46%45%Cookie <strong>security</strong>: Not sent over SSLPoor error handling: Server messageHidden fieldCross-site scripting: Reflected40%40%38%37%System information leak: Filename found in comment0% 10% 20% 30% 40% 50%33%It is interesting to note that nine of the top 10 vulnerabilities are represented within the top fivecategories shown in Figure 20. Based on the above chart, we can see that cross-frame scriptingaffects the most applications.53

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!