The Synopsys Cybersecurity Research Center (CyRC) examined data from thousands of commercial software security tests performed in 2020. The CyRC team measured this data against the 2021 OWASP Top 10 list of the most critical security risks to web applications.
Download the report to learn what vulnerabilities—such as cross-site scripting, remote code execution, and SQL injection—were most common in commercial software, and why relying solely on automated tests can leave organizations at risk to cyberattacks and data breaches.
Industry verticals represented in the report include software and internet, financial services, business services, manufacturing, media and entertainment, and healthcare.
Application security (AppSec) tests performed include penetration testing, dynamic application security testing (DAST), and mobile application security analyses—all designed to probe running applications the way a real-world hacker would.
The report makes it clear why a full spectrum of AppSec testing is essential to managing software risk. While “transparent box” tools such as static application security testing (SAST) can shed light on security issues early in the software development life cycle, SAST cannot uncover runtime security vulnerabilities. Likewise, several vulnerabilities cannot be detected by automated tools and need human oversight to uncover.
The Synopsys Cybersecurity Research Center (CyRC) examined anonymized data from thousands of commercial software security tests performed by Synopsys application security testing services in 2020. The CyRC team measured this data against the 2021 OWASP Top 10 list of the most critical security risks to web applications.
Out of 3,900 tests run by CyRC