CONTACT US
info@bidaiondo.com

7 out of 10 corporate web applications show access failures and data exposure

A study carried out by experts from the Kaspersky Security Assessment team has identified the most dangerous and widespread vulnerabilities in internally developed corporate web applications. Between 2021 and 2023, flaws related to access control and data protection were found in the majority of the applications examined, totaling several dozen. The largest number of high-risk vulnerabilities were SQL injections.

Corporate web applications such as social networks, email and online services are web pages where users interact with a server through a browser. Kaspersky's latest study investigated vulnerabilities in these applications used by IT, insurance, telecommunications, cryptocurrency, e-commerce, healthcare, and government companies to identify the most common types of attacks that occur to businesses1.

The most notable vulnerabilities involved the potential for malicious use of access control flaws, as well as in the protection of sensitive data. Between 2021 and 2023, 70% of the apps examined in the study showed weaknesses in these categories.

When a vulnerability breaks access control, attackers attempt to bypass website policies that limit users' authorized permissions. This may result in unauthorized access and alteration or deletion of data, among other things. The second most common breach recorded is the exposure of sensitive information such as passwords, credit card details, medical records, personal data and sensitive business information, highlighting the need for greater security measures.

“The rating was carried out taking into account the most common vulnerabilities in web applications developed internally in various companies and their risk level. For example, one of these vulnerabilities could allow attackers to steal user authentication data, while another could help execute malicious code on the server, each with varying degrees of consequences for business continuity and resilience. This is reflected in our rankings based on the team's practical experience in carrying out security analysis projects,” explains Oxana Andreeva, security expert on the Kaspersky Security Assessment team.

Likewise, Kaspersky experts analyzed the danger posed by these defects in the companies mentioned above. According to the study, the largest proportion of high-risk vulnerabilities were associated with SQL injections, specifically, 88% of all SQL injection vulnerabilities analyzed were considered high risk. On the other hand, analysts found another major flaw linked to weak passwords used by users, with a total of 78% of vulnerabilities classified as high risk. According to the Kaspersky Security Assessment team, only 22% of all web applications studied had weak passwords. This may be because the applications included in the study sample were run on real systems, not test versions.

Fixing vulnerabilities found in web applications will help companies protect sensitive data and avoid compromising these apps, as well as related systems. To improve security and detect possible attacks, the Kaspersky Security Assessment team recommends:

     Use secure software, such as Secure Software Development Lifecycle (SSDLC).
     Perform periodic security assessments on applications.
     Use logging and monitoring mechanisms to track application performance.

To delve deeper into the study, visit the Securelist website. The vulnerabilities described in the research align with the categories and subcategories of the OWASP Top Ten classification.

Last news

base_url:
host: www.bidaiondo.com
REQUEST_URI: /articles/7-out-of-10-corporate-web-applications-show-access-failures-and-data-exposure
path: /news/would-you-pay-e2-49-a-month-for-more-stickers-or-the-ability-to-change-the-look-of-whatsapp-whatsapp-thinks-so
¿Pagarías 2,49 € al mes por tener más stickers o poder cambiar la apariencia de Whatsapp? Whatsapp cree que sí
Whatsapp prepara el lanzamiento de Whatsapp Plus, una nueva suscripción de pago que permitirá a sus usuarios acceder a funciones ampliadas para la app de mensajería. Qué novedades incluye el nuevo Whatsapp Plus Tal y...
base_url:
host: www.bidaiondo.com
REQUEST_URI: /articles/7-out-of-10-corporate-web-applications-show-access-failures-and-data-exposure
path: /noticias/instagram-lanza-instants-en-espana-y-en-italia-comparte-imagenes-espontaneas-con-tus-amigos-que-desapareceran-en-24-horas
Instagram lanza Instants en España y en Italia: comparte imágenes espontáneas con tus amigos que desaparecerán en 24 horas
Y tú te estarás preguntando: “¿pero si eso ya existía, no?” Pues sí marketer, pues sí. Las instantáneas existen en la aplicación normal de Instagram, es una función nueva que...

online trading systems.

We show you the best way to market products and services online, through a professional service of installation, management and maintenance of your virtual store

We program to suit you

We help you achieve operational excellence in all your business processes, whether they are production, logistics, service or office processes. In addition, we assure you to maintain continuous improvement in your management.

Bidaiondo Articles

This is the new GPT-5.5: 5 key features of the model that already solves complex tasks autonomously

It's been a busy few days (very busy, in fact) at OpenAI, which seems to have finally responded to the "code red" activated by its CEO, Sam Altman, at the end of last year. In the same week that we saw the launch of Images 2.0 and Workspace Agents, a new version of GPT, 5.5, has arrived. 5 key points about the new GPT 5.5 1. Solving complex problems Specifically, the company seems very proud of this new model's ability...

Ver más »

No more digging through your inbox: Google begins rolling out its AI Overviews in Gmail

At its Cloud Next event, Google announced the arrival of AI Overviews to Gmail. This feature, based on Gemini 3 technology, will allow Google's email platform to generate AI-powered summaries from your emails. Currently, this feature is only available in English in the United States and can be used on personal accounts with the Google AI Pro and Google AI Ultra plans, as well as on professional or educational accounts with a Google Workspa...

Ver más »