CONTACT US
info@bidaiondo.com
A study carried out by experts from the Kaspersky Security Assessment team has identified the most dangerous and widespread vulnerabilities in internally developed corporate web applications. Between 2021 and 2023, flaws related to access control and data protection were found in the majority of the applications examined, totaling several dozen. The largest number of high-risk vulnerabilities were SQL injections.
Corporate web applications such as social networks, email and online services are web pages where users interact with a server through a browser. Kaspersky's latest study investigated vulnerabilities in these applications used by IT, insurance, telecommunications, cryptocurrency, e-commerce, healthcare, and government companies to identify the most common types of attacks that occur to businesses1.
The most notable vulnerabilities involved the potential for malicious use of access control flaws, as well as in the protection of sensitive data. Between 2021 and 2023, 70% of the apps examined in the study showed weaknesses in these categories.
When a vulnerability breaks access control, attackers attempt to bypass website policies that limit users' authorized permissions. This may result in unauthorized access and alteration or deletion of data, among other things. The second most common breach recorded is the exposure of sensitive information such as passwords, credit card details, medical records, personal data and sensitive business information, highlighting the need for greater security measures.
“The rating was carried out taking into account the most common vulnerabilities in web applications developed internally in various companies and their risk level. For example, one of these vulnerabilities could allow attackers to steal user authentication data, while another could help execute malicious code on the server, each with varying degrees of consequences for business continuity and resilience. This is reflected in our rankings based on the team's practical experience in carrying out security analysis projects,” explains Oxana Andreeva, security expert on the Kaspersky Security Assessment team.
Likewise, Kaspersky experts analyzed the danger posed by these defects in the companies mentioned above. According to the study, the largest proportion of high-risk vulnerabilities were associated with SQL injections, specifically, 88% of all SQL injection vulnerabilities analyzed were considered high risk. On the other hand, analysts found another major flaw linked to weak passwords used by users, with a total of 78% of vulnerabilities classified as high risk. According to the Kaspersky Security Assessment team, only 22% of all web applications studied had weak passwords. This may be because the applications included in the study sample were run on real systems, not test versions.
Fixing vulnerabilities found in web applications will help companies protect sensitive data and avoid compromising these apps, as well as related systems. To improve security and detect possible attacks, the Kaspersky Security Assessment team recommends:
Use secure software, such as Secure Software Development Lifecycle (SSDLC).
Perform periodic security assessments on applications.
Use logging and monitoring mechanisms to track application performance.
To delve deeper into the study, visit the Securelist website. The vulnerabilities described in the research align with the categories and subcategories of the OWASP Top Ten classification.
Knowing the best time to post on Facebook will make a big difference in the reach and engagement of your posts. Although there's no magic formula, understanding user habits and taking advantage of the key moments when they're most active will be very useful in boosting your strategy on Meta's social network. What are the best times and days to post on Facebook? Looking at the engagement map for this social network, we discover that mo...
123456, 1245, 1111, 0000, password… These are some of the most common passwords in the world (and therefore some of the most insecure). You've probably used them at some point, whether to activate your phone, access your email, or log into your social media account. Maybe even Facebook. However, in recent years, we've seen signs that the era of traditional passwords is coming to an end, and the social network with the most users in...
BIDAIONDO SL, as the party responsible for the website www.bidaiondo.com, uses its own operating cookies and those of third parties of an analytical nature to allow the use of the website, analyze our services and show you information related to your preferences based on a profile drawn up from of your browsing habits (for example: pages visited). Please bear in mind that, if you do not activate some types of cookies, such as operational and analytical cookies, your experience of using this website may be affected. You can obtain more information and configure your preferences in the CONFIGURE option that appears below, you can reject cookies in the REJECT AND CLOSE option or accept all cookies and continue browsing in the ACCEPT AND CLOSE option.
Data privacy seems important to you, and it is to us too. We store cookie data for 13 months. If you want to know more, you can visit our pages Privacy Policy y Cookies policy. Do you know what cookies are? Cookies are files that are used by virtually all websites. When browsing our page, they are installed in your browser or device to ensure that the website works correctly and store information about your visit. The data provided by cookies treat the user anonymously and in no case do they store personal information.
The data collected by the cookies we use are:
- Addresses IP
- References of visited pages
- References of downloaded files