In a comprehensive examination of the years spanning from 2021 to 2023, cybersecurity experts at Kaspersky Security Assessment have unearthed a concerning number of vulnerabilities lurking within corporate web applications developed in-house.
The study sheds light on the pervasive risks faced by organisations due to flaws predominantly centred around access control and data protection. The web applications scrutinised in the study represent vital components of organisations’ online infrastructure, facilitating a broad scope of services and interactions with users.
Of particular alarm were the vulnerabilities linked to SQL injections, making up a lion’s share of high-risk vulnerabilities identified during the investigation. These vulnerabilities, hiding within the intricate architecture of corporate web applications, pose formidable threats to enterprises, potentially compromising sensitive data or opening pathways for unauthorised access.
Access control deficiencies and lapses in data protection emerged as the Achilles’ heel of many applications, collectively accounting for a staggering 70% of the vulnerabilities scrutinised.
Moreover, the study flagged weak user passwords as a glaring vulnerability, with a staggering 78% of such weaknesses categorised as high-risk. Intriguingly, despite the prevalence of weak passwords, only 22% of the web applications surveyed were found to harbour this vulnerability, suggesting potential disparities between test versions and live systems.
The study’s findings were done in response to the OWASP Top Ten application security risks.
“As we followed their rankings, we noticed that the way we ranked major vulnerabilities was different. Being curious, we decided to find out just how big the difference was,” said Oxana Andreeva, security expert at Kaspersky in a report on the matter.
“That’s why we set up our own rankings that reflected our take on the most widespread and critical web application vulnerabilities as viewed through a prism of eight years’ experience.”
Recommended reading
- Kaspersky Flag Malicious Apps Problem on Google Play Store
- NCSC Releases New Tool to Scan for Malware Vulnerabilities
- Web Apps Are Easy Targets in Ongoing Vulnerability Crisis
The study’s findings resonate with the OWASP Top Ten rating categories, reinforcing the imperative of addressing these vulnerabilities to fortify the defences of web applications and safeguard sensitive data against compromise.
To mitigate these risks, the Kaspersky Security Assessment team advocates for the adoption of secure software development practices, coupled with regular security assessments and the deployment of vigilant monitoring mechanisms to swiftly detect and neutralise potential threats.





