Open source components remain vulnerable to malicious or unauthorized activity
2017 State of Software Security Report Veracode announced findings from the 2017 State of Software Security Report , a comprehensive review of application security testing data from scans conducted by a base of more than 1,400 customers. Among other industry trends such as vulnerability fix rates and percent of applications with vulnerabilities, the report exposes the pervasive risk from vulnerable open source components. Researchers found that 88 percent of Java applications contain at least one vulnerable component, making them susceptible to widespread attacks. This is in part because fewer than 28 percent of companies conduct regular composition analysis to understand which components are built into their applications. “The universal use of components in application development means that when a single vulnerability in a single component is disclosed, that vulnerability now has the potential to impact thousands of applications – making many of them breachable with a single e...