HomeSecuritySonatype warns about insecure Java component

Sonatype warns about unsafe Java component

The company that hosts the Maven Central Repository says that one in sixteen downloads is for a Java that contains a known security flaw.
Sonatype claims that developers typically download 31 billion Java components annually, with over 1,000 new components and over 10,000 new component versions created daily.

Sonatype estimates that between 80 and 90 percent of today's enterprise code is actually built on open source components, imported from public repositories.

Java
Because security vulnerabilities are public, and because Sonatype has access to server statistics, it is in a position – more than anyone else – to warn developers about the dangers of using insecure or outdated components within their code.
This warning is doubly important for companies, given that if an attacker compromises an application built with the vulnerable components, the result can have a profound financial impact.

After studying 3,000 organizations and over 25,000 enterprise applications across a variety of industries, Sonatype tells us that a company downloads about 5,000 unique components each year.
The older the components, the more likely they are to contain a security vulnerability. Worse still, 97% of all these components cannot be easily audited.
If a company wanted to fix 10% of the security flaws in 2,000 applications, it would cost a whopping $7.42 million.

These issues introduce the need for software supply chain management to prevent future vulnerabilities.
Removing vulnerable components should also be a top priority for the communities behind these projects.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS