TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Programming

Java Applications: A Frontrunner for Vulnerabilities, Report Reveals

Paul Balo by Paul Balo
October 20, 2016
in Programming
Share on FacebookShare on Twitter

Massachusetts-based security firm, Veracode, recently unveiled its annual State of Software Security Report for 2016 . A significant takeaway from the report lies in the fact that software development’s open-source components account for a substantial proportion of security vulnerabilities. The report is grounded on an extensive study encompassing over 300,000 assessments performed on enterprise applications over 18 months.

In the labyrinth of programming languages, Java emerged at the forefront with 97% of applications written in it found to harbor at least one vulnerability. These vulnerabilities, which range from severe to low-grade, stem from their component parts, i.e., bits of code that developers utilize to pen software. Consequently, 25% of all Java applications reportedly possess a known vulnerable component playing a substantial role in Java’s high vulnerability ratings.

Interestingly, Java, a product of Sun Microsystems in 1995 initially, was subsequently taken over by Oracle, post their 2009 acquisition of the initial company. Java has developed a notoriety for its inherent security flaws, prompting a series of frequent security patches.

Chris Wysopal, co-founder and chief technology officer of Veracode, alerted Fortune to the impending danger residing in code components. He stated, “there’s a danger in code components being reused throughout many applications without developers necessarily realizing it…a lot of risk is inherited, and people don’t know, because it’s two steps removed.”

The report also highlights that information leakage at 72% and cryptographic issues at 65% stand as the main sources of vulnerabilities.

It’s not all doom and gloom, though. The report lauded corporate developers for their improvement in delivering secure applications. However, third-party developers are not keeping pace, exhibiting a deteriorating performance. This performance divide draws a stark contrast between in-house developed applications, which passed the industry benchmark 39% of the time (a rise from 37% last year), and third-party developed applications achieving a mere 25% pass rate, a drop from 28% last year.

Occasionally, these software disparities force companies to insource application maintenance, deeming vendor costs exorbitant. Moreover, some vendors, having received their payment, may not display the same dedication towards routine application updates.

Interestingly, the health sector shows the lowest vulnerability fix rate across the industries, a fact that poses immense concern according to the report. A common assumption might be that tech wizards, i.e., security professionals, would top the fix rate. However, the report indicates that only about one-third of flaws get rectified by security experts. On the other hand, the manufacturing industry leads the pack, managing to fix two-thirds of known/reported flaws efficiently.

In conclusion, the report offers food for thought for enterprises relying on vulnerable platforms like Java, pressing the need for constant updates and security checks. The lessons learned here offer a road map towards better software development practices and more secure enterprise applications.

Related Posts:

  • winUpdate-2
    Microsoft Fixes 77 Vulnerabilities in March Patch Tuesday
  • microsofts-surface-duo-dualscreen-androi-5f1f3d057e8c350ae07dd862-1-jul-28-2020-15-24-20-poster
    Microsoft Patch Tuesday Fixes 63 Bugs, 1 Zero-Day
  • OAI_GPT-5.2-Codex_ArtCard_16x9.
    OpenAI Unveils GPT-5.2-Codex
  • 020tYFWBL4Yz8jIIFUdKDR1-22
    A Fix to Microsoft Windows Defender And Security Flaws
  • BLOG-3216_1
    Cloudflare Boosts Developer Security with Shift-Left…
  • bluehammer-will-dormann
    BlueHammer Windows Exploit Exposes Microsoft Bug…
  • blog5f352fc3b2393_wp
    Hackers Exploit Popular WordPress Backup Tool Used…
  • generic-security-logo-blocks-github
    GitHub Expands AI Security Detections Across More Languages

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: appapplicationcyber securitydeveloperjavaprogrammingresearchsecurity
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Elon Musk Hits $1.1 Trillion as SpaceX Surpasses $2 Trillion Valuation June 13, 2026
  • SpaceX Prices Record $75 Billion IPO as Elon Musk Nears Trillionaire Status June 12, 2026
  • DoorDash Launches AI Chatbot for Food Orders June 12, 2026
  • Pool Launches App That Makes Screenshots More Useful June 12, 2026
  • Deezer Launches Tool to Detect AI-Generated Music June 12, 2026
  • Coinbase Introduces Platform for Agents to Trade Assets and Buy Premium Insights June 12, 2026
  • Meta Expands Edits App With AI Features and Desktop Access June 12, 2026
  • Ready-made LMS and custom development. Pros and cons of each path. June 11, 2026
  • TELCOs Pay 75 Million Users For Poor Network Service June 10, 2026
  • Anthropic Launches Claude Fable 5, Bringing Mythos-Class AI to the Public June 10, 2026
  • Discord Data Breach Reportedly Impacts Over 10 Million Users June 10, 2026
  • TikTok Removed Four Million Videos & Disrupted 86,000 LIVE Sessions In Nigeria June 10, 2026

Browse Archives

June 2026
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.